A vulnerability was found in openviglet shio up to 0.3.8....
Moderate severity
Unreviewed
Published
Jul 31, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 31, 2025
Published to the GitHub Advisory Database
Jul 31, 2025
A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
References