CVE-2026-91751
Received Received - Intake

Path Traversal in Flextype CMS

Vulnerability report for CVE-2026-91751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
flextype cms to 1.0.0-alpha.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Flextype CMS through 1.0.0-alpha.3 has a path traversal flaw in its Entries REST API. The vulnerability occurs because the id and new_id parameters are not properly validated, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use directory traversal sequences like ../ to escape the project entries directory and manipulate arbitrary files on the filesystem.

Detection Guidance

To detect this vulnerability, monitor API requests to the Flextype Entries REST API for unusual parameters containing traversal sequences like '../'. Check server logs for file operations outside the entries directory. Use tools like curl to test if the API allows path traversal by sending requests with manipulated id or new_id values.

Impact Analysis

If you are an API token holder, an attacker could exploit this to read sensitive files, overwrite critical system files, or create malicious files anywhere on the server. This could lead to data breaches, system compromise, or denial of service. Even without direct access, if the CMS is exposed to untrusted networks, attackers could gain control over the server.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches exposing personal or health information, leading to legal penalties, fines, and reputational damage for organizations handling regulated data.

Mitigation Strategies

Immediately upgrade Flextype CMS to a patched version beyond 1.0.0-alpha.3. If upgrading is not possible, restrict API token access and disable the Entries REST API if unused. Implement strict input validation for id and new_id parameters to prevent path traversal sequences.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart