{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lamp-cloud/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19757"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lamp-cloud"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Dromara"],"content_html":"\u003cp\u003eDromara lamp-cloud, a cloud-based development platform, contains a critical path traversal vulnerability (CVE-2026-19757) affecting all versions up to 5.10.0. The vulnerability is located within the File-Upload Controller component, specifically in FileAnyoneController.java. An unauthenticated remote attacker can exploit this flaw by manipulating the 'bucket' or 'bizType' parameters, which are improperly sanitized before being used in file system operations. This allows the attacker to traverse directories and access files outside the intended scope on the server hosting the application. Public proof-of-concept exploits exist, and the maintainers have not yet provided a resolution. Given the remote, unauthenticated nature of this vulnerability, it poses a significant risk to the confidentiality and integrity of affected deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify endpoints running Dromara lamp-cloud.\u003c/li\u003e\n\u003cli\u003eAttacker probes the file upload functionality hosted by FileAnyoneController.java.\u003c/li\u003e\n\u003cli\u003eAttacker constructs an HTTP request targeting the affected controller endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects path traversal sequences (e.g., ../../) into the 'bucket' or 'bizType' query parameters.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate or sanitize the path input provided in the parameters.\u003c/li\u003e\n\u003cli\u003eThe server-side code resolves the path relative to the application's root directory, escaping the target storage folder.\u003c/li\u003e\n\u003cli\u003eThe server returns the contents of sensitive files or enables unauthorized write operations to the file system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files from the server's file system. Depending on the server's configuration and the privileges of the service account running the lamp-cloud application, this may lead to the exfiltration of configuration files, credentials, or sensitive application data. The scope of impact is potentially high for any organization hosting this software in an internet-facing configuration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of Dromara lamp-cloud instances in your environment. Until a vendor patch is available, implement the following:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for requests containing path traversal sequences (e.g., \u0026quot;../\u0026quot;) targeting the FileAnyoneController.java path.\u003c/li\u003e\n\u003cli\u003eRestrict access to the File-Upload Controller endpoints via WAF rules or reverse proxy configurations.\u003c/li\u003e\n\u003cli\u003eAudit application service account permissions to ensure the principle of least privilege, minimizing the damage of potential file read attempts.\u003c/li\u003e\n\u003cli\u003eMonitor for CVE-2026-19757 exploitation attempts by matching web logs against suspicious character patterns in URI parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T02:05:55Z","date_published":"2026-08-14T02:05:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-lamp-cloud-path-traversal/","summary":"An unauthenticated remote path traversal vulnerability in Dromara lamp-cloud allows attackers to access unauthorized files via the FileAnyoneController component.","title":"Path Traversal in Dromara lamp-cloud","url":"https://feed.craftedsignal.io/briefs/2026-08-lamp-cloud-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Lamp-Cloud","version":"https://jsonfeed.org/version/1.1"}