Back

MEDIUM

yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal

Published Aug 19, 2026

Description

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDownload/resourceDownload of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java of the component Common Download Endpoint. Performing a manipulation of the argument fileName/resource results in path traversal. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Aug 21, 2026
NVD
Status Deferred
Modified Aug 21, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Aug 19, 2026
Updated Aug 21, 2026
Exploited since n/a
EUVD-2026-62846