{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/dtstack/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19762"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Taier (1.4.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal"],"_cs_type":"advisory","_cs_vendors":["DTStack"],"content_html":"\u003cp\u003eA path traversal vulnerability exists in DTStack Taier 1.4.0, specifically within the Chunk-Check endpoint handled by the FileChunkController.java file. An unauthenticated remote attacker can exploit the 'Paths.ge' function by manipulating the 'Name' argument. This flaw allows the attacker to bypass directory restrictions and access arbitrary files on the underlying filesystem. Publicly available exploit material exists for this vulnerability, increasing the risk of exploitation. Given the potential for unauthorized file access, organizations utilizing DTStack Taier 1.4.0 are advised to prioritize remediation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote, unauthenticated attacker to read arbitrary files from the server hosting the Taier application. This can lead to the exposure of sensitive configuration files, credentials, or application data, potentially compromising the integrity and confidentiality of the host environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade DTStack Taier to a patched version once available to address CVE-2026-19762.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the 'Name' argument within the 'FileChunkController' endpoint to prevent path traversal characters such as '../'.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for requests to the 'Chunk-Check' endpoint containing path traversal sequences or anomalous filename parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T02:06:06Z","date_published":"2026-08-14T02:06:06Z","id":"https://feed.craftedsignal.io/briefs/2026-08-taier-path-traversal/","summary":"DTStack Taier 1.4.0 is susceptible to a remote path traversal vulnerability (CVE-2026-19762) in the Chunk-Check endpoint, allowing unauthenticated attackers to manipulate file paths.","title":"Path Traversal Vulnerability in DTStack Taier","url":"https://feed.craftedsignal.io/briefs/2026-08-taier-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - DTStack","version":"https://jsonfeed.org/version/1.1"}