MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normalization or path validation. An attacker who controls a filename returned by a remote cloud storage API can include traversal sequences ../ in the filename to cause downloaded content to be written outside the configured download directory, potentially overwriting arbitrary files including configuration or plugin files reachable by the application process.
History

Sat, 06 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Jxxghp
Jxxghp moviepilot
Vendors & Products Jxxghp
Jxxghp moviepilot

Fri, 05 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normalization or path validation. An attacker who controls a filename returned by a remote cloud storage API can include traversal sequences ../ in the filename to cause downloaded content to be written outside the configured download directory, potentially overwriting arbitrary files including configuration or plugin files reachable by the application process.
Title MoviePilot Path Traversal via Cloud Storage Download Handlers
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-05T21:42:49.274Z

Reserved: 2026-06-05T19:08:04.224Z

Link: CVE-2026-11416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T22:16:47.127

Modified: 2026-06-05T22:16:47.127

Link: CVE-2026-11416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-06T01:00:09Z