← Back to CVE List
CVE-2026-105174NVD
Vulnerability Summary
A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 6e481078cfba6388a67ca2d9792288405019ba3e. Applying a patch is the recommended action to fix this issue.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.4 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a Gerapy >= 0.9.0
- n/a Gerapy >= 0.9.1
- n/a Gerapy >= 0.9.2
- n/a Gerapy >= 0.9.3
- n/a Gerapy >= 0.9.4
- n/a Gerapy >= 0.9.5
- n/a Gerapy >= 0.9.6
- n/a Gerapy >= 0.9.7
- n/a Gerapy >= 0.9.8
- n/a Gerapy >= 0.9.9
- n/a Gerapy >= 0.9.10
- n/a Gerapy >= 0.9.11
- n/a Gerapy >= 0.9.12
- n/a Gerapy >= 0.9.13
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/413406
- https://vuldb.com/vuln/413406/cti
- https://vuldb.com/cve/CVE-2026-105174
- https://vuldb.com/submit/970586
- https://github.com/Gerapy/Gerapy/issues/317
- https://github.com/Gerapy/Gerapy/pull/319
- https://github.com/Gerapy/Gerapy/commit/6e481078cfba6388a67ca2d9792288405019ba3e
- https://github.com/Gerapy/Gerapy/