Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in WookTeam v1.6.6 and Earlier | |
| Weaknesses | CWE-22 |
Mon, 05 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-05T14:22:29.647Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88394
No data.
Status : Received
Published: 2026-10-05T15:17:22.997
Modified: 2026-10-05T15:17:22.997
Link: CVE-2026-88394
No data.
OpenCVE Enrichment
Updated: 2026-10-05T15:30:20Z