Vendor
Dinky v1.2.5 contains a path traversal vulnerability in the /download/uploadFromRsByLocal endpoint, which is protected by a hardcoded authentication token, allowing unauthenticated attackers to achieve arbitrary file write and remote code execution.