CVE-2026-72569: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in cube-root directory-serve
CVE-2026-72569 is a critical path traversal vulnerability in cube-root's directory-serve application up to version 1.3.7. It allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
AI Analysis
Technical Summary
This vulnerability (CWE-22) exists in cube-root directory-serve versions prior to 1.3.8. It improperly limits pathname access, enabling unauthenticated remote attackers to perform path traversal attacks that delete files outside the designated directory if the --delete option is enabled. The CVSS 3.1 score is 9.1, reflecting network attack vector, no privileges required, no user interaction, and high impact on integrity and availability.
Potential Impact
An attacker can remotely delete arbitrary files outside the intended directory without authentication, potentially causing significant disruption or denial of service. Confidentiality is not impacted, but integrity and availability are severely affected.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Users should upgrade to version 1.3.8 or later once available. Until then, avoid running directory-serve with the --delete option or restrict its network exposure to trusted environments. Monitor vendor advisories for updates.
CVE-2026-72569: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in cube-root directory-serve
Description
CVE-2026-72569 is a critical path traversal vulnerability in cube-root's directory-serve application up to version 1.3.7. It allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
CVSS v3.1
Score 9.1critical
Affected software
cube-root
directory-serve
pkg:npm/cube-root/directory-serveRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-22) exists in cube-root directory-serve versions prior to 1.3.8. It improperly limits pathname access, enabling unauthenticated remote attackers to perform path traversal attacks that delete files outside the designated directory if the --delete option is enabled. The CVSS 3.1 score is 9.1, reflecting network attack vector, no privileges required, no user interaction, and high impact on integrity and availability.
Potential Impact
An attacker can remotely delete arbitrary files outside the intended directory without authentication, potentially causing significant disruption or denial of service. Confidentiality is not impacted, but integrity and availability are severely affected.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Users should upgrade to version 1.3.8 or later once available. Until then, avoid running directory-serve with the --delete option or restrict its network exposure to trusted environments. Monitor vendor advisories for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T10:32:53.853Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a79ae6ebf8831d5398afd09
Added to database: 08/10/2026, 10:56:46 UTC
Last enriched: 08/17/2026, 15:57:11 UTC
Last updated: 09/24/2026, 01:47:44 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.