Threats Tagged 'cve-2026-19054'
View all threats tagged with 'cve-2026-19054'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-19054'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. (CVE-2026-19054)CVE-2026-19054 0 A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. Performing a manipulation of the argument filePath results in path traversal. The attack is only possible with local access. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | GCVE Database | 08/07/2026, 00:31:15 UTC Added: 08/07/2026, 05:56:53 UTC |
CVE-2026-19054: Path Traversal in Lspace-io lspace-serverCVE-2026-19054 0 CVE-2026-19054 is a path traversal vulnerability in the Lspace-io lspace-server affecting file operations in the Repositories File API. The flaw allows manipulation of the filePath argument in functions such as fileExists, readFile, writeFile, and deleteFile, potentially enabling unauthorized file access. Exploitation requires local access to the system. The product uses continuous delivery with rolling releases, so specific affected or fixed versions are not identified. The vendor has not yet responded or provided a fix. Join the discussion | CVE Database V5 | 08/06/2026, 15:30:10 UTC Added: 08/06/2026, 22:13:09 UTC |
Showing 1 to 2 of 2 results