<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-91751 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-91751/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 01:38:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-91751/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Flextype CMS Entries REST API</title><link>https://feed.craftedsignal.io/briefs/2026-09-flextype-cms-traversal/</link><pubDate>Tue, 15 Sep 2026 01:38:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-flextype-cms-traversal/</guid><description>Flextype CMS versions through 1.0.0-alpha.3 are vulnerable to path traversal via the Entries REST API, allowing authenticated attackers to read, create, or overwrite arbitrary files on the filesystem.</description><content:encoded><![CDATA[<p>Flextype CMS versions up to and including 1.0.0-alpha.3 contain a critical path traversal vulnerability (CVE-2026-91751) within the Entries REST API. The vulnerability stems from insufficient input validation of the 'id' and 'new_id' parameters when processing API requests. This flaw permits an attacker who possesses a valid API token to escape the intended project entries directory. By utilizing path traversal sequences, an attacker can navigate the filesystem to read sensitive configuration or application files, or create and overwrite files in arbitrary directories. Given the potential for arbitrary file creation and modification, successful exploitation could lead to full system compromise or remote code execution depending on the attacker's ability to inject payloads into executable paths or configuration files.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized access to the underlying filesystem of the server hosting Flextype CMS. This represents a significant risk to the integrity and confidentiality of the entire hosting environment, as it grants API token holders the ability to read sensitive data, corrupt application files, or potentially gain further control over the host via arbitrary file write operations.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and remediation teams:</p>
<ul>
<li>Upgrade Flextype CMS installations to a version beyond 1.0.0-alpha.3 immediately to address CVE-2026-91751.</li>
<li>Audit existing API tokens to ensure only necessary users maintain access and revoke any suspected compromised tokens.</li>
<li>Monitor web server access logs for anomalous requests containing path traversal patterns (e.g., ../) targeting the Entries REST API endpoints.</li>
<li>Restrict access to the Entries REST API at the network or web server configuration level for untrusted network segments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>web-vulnerability</category><category>cve-2026-91751</category></item></channel></rss>