CVE-2026-52349
Received Received - Intake

Directory Traversal in Menyoo 2.0 via Spooner File Management

Vulnerability report for CVE-2026-52349, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: MITRE

Description

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions save/folder/rename functionality, PedComponentChanger create folder/createfile/rename functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
itsjustcurtis menyoo to 729aa48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-52349 is a Directory Traversal vulnerability in Menyoo 2.0 versions before commit 729aa48. It allows a local attacker to execute arbitrary code through file management features like Spooner, VehicleSpawner, WeaponOptions, and PedComponentChanger by manipulating file paths to access restricted directories.

Detection Guidance

Check for Menyoo 2.0 versions before commit 729aa48. Inspect file management operations in Spooner, VehicleSpawner, WeaponOptions, and PedComponentChanger for unusual path handling or directory traversal attempts like '..' or path separators.

Impact Analysis

An attacker could exploit this to overwrite critical files in different directories, potentially causing system instability or executing malicious code. This is particularly risky for multiplayer environments like FiveM where modified versions of Menyoo are used.

Compliance Impact

The vulnerability could lead to unauthorized file access or overwrites, potentially compromising data integrity and confidentiality. This may impact compliance with standards like GDPR (data protection) or HIPAA (health data security) by increasing risks of data breaches or unauthorized modifications.

Mitigation Strategies

Update to the latest version of MenyooSP with commit 729aa48 or later. Ensure the 'IsSafePath' validation is enforced in file operations. Remove or restrict write access to sensitive directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52349. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart