An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app-api/infra/file/upload.
CVE-2026-71805
NONE
EPSS 0.18%
Updated Sep 10, 2026
An
CVE Details
CVE ID
CVE-2026-71805
Published Date
Sep 10, 2026
Vendor
An
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
7.2th percentile (higher than 7.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory