Vulnerability Description
MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normalization or path validation. An attacker who controls a filename returned by a remote cloud storage API can include traversal sequences ../ in the filename to cause downloaded content to be written outside the configured download directory, potentially overwriting arbitrary files including configuration or plugin files reachable by the application process.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/jxxghp/MoviePilot
- https://github.com/jxxghp/MoviePilot/commit/a0b3800f6bf4857bf4f889a63d44350eb838
- https://github.com/jxxghp/MoviePilot/issues/5894
- https://github.com/jxxghp/MoviePilot/issues/5894
FAQ
What is CVE-2026-11416?
CVE-2026-11416 is a vulnerability with a CVSS score of 8.1 (HIGH). MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured downl...
How severe is CVE-2026-11416?
CVE-2026-11416 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11416?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.