{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azfilezfile/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zfile:zfile:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91144"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZFile (\u003c= 5.0.5)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","web-vulnerability","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["ZFile"],"content_html":"\u003cp\u003eZFile, a popular file directory software, contains a critical path traversal vulnerability (CVE-2026-91144) in versions through 5.0.5. The vulnerability resides within the download endpoint, which fails to adequately validate user-supplied file paths against the base directory defined for a specific share link. An attacker who possesses a valid share link can manipulate query parameters to access and retrieve files outside of the intended, restricted directory. This flaw effectively grants unauthorized read access to the underlying server filesystem, potentially leading to the exposure of sensitive configuration files, environment variables, or other private data stored on the host. The issue is exacerbated by the fact that the endpoint does not require authentication, making it accessible to any party with a public share link. Defenders should prioritize updating ZFile to a patched version once available and monitor access logs for anomalous path structures.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass directory restrictions and exfiltrate arbitrary files from the server. This could lead to full system information disclosure, including compromise of credentials or system configuration, depending on the server's permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of ZFile to a version newer than 5.0.5 immediately upon release of a security patch.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for path traversal attempts targeting the ZFile download endpoint.\u003c/li\u003e\n\u003cli\u003eConfigure web application firewalls to alert on requests containing sequences such as \u0026quot;../\u0026quot; or \u0026quot;..\\\u0026quot; in query parameters directed at ZFile download handlers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T23:36:51Z","date_published":"2026-09-14T23:36:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zfile-path-traversal/","summary":"ZFile versions through 5.0.5 are vulnerable to a path traversal attack allowing unauthenticated attackers to download arbitrary files via manipulated share link query parameters.","title":"Path Traversal Vulnerability in ZFile Download Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-zfile-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zfile:zfile:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}