In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.
CVE-2026-51906
NONE
EPSS 0.14%
Updated Oct 02, 2026
N/A
n/a:n/a
CVE Details
CVE ID
CVE-2026-51906
Published Date
Oct 02, 2026
Vendor
N/A
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.2th percentile (higher than 3.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory