Vulnerability Description
A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The patch is named 3d255865a957f3740b8724dd914502c0f44d4970. Applying a patch is the recommended action to fix this issue.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/DV0x/creative-ad-agent/
- https://github.com/DV0x/creative-ad-agent/commit/3d255865a957f3740b8724dd914502c
- https://github.com/DV0x/creative-ad-agent/issues/1
- https://vuldb.com/submit/802887
- https://vuldb.com/vuln/359926
- https://vuldb.com/vuln/359926/cti
FAQ
What is CVE-2026-7271?
CVE-2026-7271 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-age...
How severe is CVE-2026-7271?
CVE-2026-7271 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7271?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.