Pathling
Aehrc · 6 CVEs
CVE-2026-47664
HIGH
Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoning
Aug 7, 2026
CVE-2026-47663
HIGH
Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutation
Aug 7, 2026
CVE-2026-47662
HIGH
Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest outp…
Aug 7, 2026
CVE-2026-47661
HIGH
Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read
Aug 7, 2026
CVE-2026-47660
HIGH
Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration
Aug 7, 2026
CVE-2026-47659
HIGH
Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}
Aug 7, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-47664 | Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoning | HIGH | 0.21% | Aug 7, 2026 |
| CVE-2026-47663 | Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutation | HIGH | 0.41% | Aug 7, 2026 |
| CVE-2026-47662 | Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs | HIGH | 0.41% | Aug 7, 2026 |
| CVE-2026-47661 | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read | HIGH | 0.62% | Aug 7, 2026 |
| CVE-2026-47660 | Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration | HIGH | 0.54% | Aug 7, 2026 |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | HIGH | 0.62% | Aug 7, 2026 |
Showing 1 to 6 of 6 CVEs