CVE-2026-105174
Received Received - Intake

Path Traversal in Gerapy Project Management

Vulnerability report for CVE-2026-105174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 6e481078cfba6388a67ca2d9792288405019ba3e. Applying a patch is the recommended action to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gerapy gerapy to 0.9.13 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in Gerapy up to version 0.9.13. It affects the project_create function in gerapy/server/core/views.py where manipulating the project_name argument allows an attacker to traverse outside intended directories. The exploit is possible remotely and has been publicly disclosed.

Detection Guidance

Check Gerapy logs for unauthorized project upload attempts or path traversal patterns in the project_name parameter. Inspect uploaded ZIP files for entries containing ../ or similar path traversal sequences. Verify if the project_upload endpoint is accessible without authentication by testing unauthenticated POST requests to /api/project/upload.

Impact Analysis

An attacker could upload malicious files to unintended locations on the server, potentially overwriting existing files or injecting malicious code. This could lead to unauthorized access, data theft, or remote code execution if the server processes the malicious files.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Compliance may be compromised if sensitive data is exposed or altered due to the path traversal.

Mitigation Strategies

Apply the patch from commit 6e481078cfba6388a67ca2d9792288405019ba3e to enforce authentication and validate ZIP file paths. Ensure the @permission_classes([IsAuthenticated]) decorator is enabled for the project_upload endpoint. Monitor for unauthorized upload attempts and restrict access to the /api/project/upload endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart