Vulnerability Description
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/zfile-dev/zfile
- https://github.com/zfile-dev/zfile/blob/5.0.5/src/main/java/im/zhaojun/zfile/mod
- https://github.com/zfile-dev/zfile/issues/826
- https://www.vulncheck.com/advisories/zfile-through-5.0.5-share-entry-filter-bypa
FAQ
What is CVE-2026-91144?
CVE-2026-91144 is a vulnerability with a CVSS score of 7.5 (HIGH). ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query para...
How severe is CVE-2026-91144?
CVE-2026-91144 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91144?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.