CVE-2026-51907
Received Received - Intake

Path Traversal in TaskingAI QR Code Generator Plugin

Vulnerability report for CVE-2026-51907, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
taskingai taskingai 0.3.0
taskingai qr_code_generator From 0.3.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-51907 is a path traversal vulnerability in TaskingAI v0.3.0's QR Code Generator plugin. The flaw exists in the save_base64_image function where the project_id parameter is directly used to construct file paths without validation. Attackers can manipulate this parameter to write files to arbitrary locations on the server filesystem using path traversal sequences like ../../../.

Detection Guidance

To detect this vulnerability, monitor for unexpected file writes in arbitrary locations on the server filesystem. Check for files created outside the intended storage directory (volume/imgs/p/) and inspect POST requests to /v1/execute with the qr_code_generator bundle and generate_qr_code plugin. Look for project_id parameters containing path traversal sequences like ../../../.

Impact Analysis

This vulnerability allows attackers to write arbitrary files to any location on the server filesystem. This could lead to unauthorized file manipulation, potential data corruption, or overwriting critical system files. While it does not allow arbitrary code execution, it poses risks of unauthorized access and system compromise depending on the server's configuration.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized access to sensitive data or system files. It undermines data integrity and confidentiality controls required by these regulations. Organizations may face compliance violations, legal penalties, or reputational damage if exploited.

Mitigation Strategies

Immediately update TaskingAI to a patched version if available. If not, disable the QR Code Generator plugin or restrict access to the POST /v1/execute endpoint. Implement input validation for the project_id parameter to prevent path traversal sequences. Ensure file paths are normalized and contained within the storage directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51907. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart