CVE-2026-88394
Received Received - Intake

Directory Traversal in WookTeam Project Export

Vulnerability report for CVE-2026-88394, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an arbitrary file read issue in WookTeam v1.6.6 and earlier. It allows attackers to download sensitive files from the server by exploiting a directory traversal flaw in the /api/project/task/export endpoint. The attack involves sending a crafted JSON payload with a path traversal sequence (e.g., ../.env) in the file parameter, which bypasses directory restrictions and streams any readable file.

Detection Guidance

To detect this vulnerability, check if your WookTeam instance (v1.6.6 or earlier) has the /api/project/task/export endpoint exposed. Send a crafted request with a path traversal payload like {"projectid":1,"file":"../.env"} and observe if sensitive files are returned. Monitor server logs for unusual export requests or file access patterns.

Impact Analysis

An attacker could exploit this to access sensitive files like .env, which may contain credentials such as database passwords or application keys. This could lead to unauthorized access, data breaches, or further compromise of the server. The attack requires an account but bypasses proper permission checks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. Exposure of credentials or personal data may result in regulatory fines, legal liabilities, and reputational damage due to non-compliance with data protection standards.

Mitigation Strategies

Immediately upgrade WookTeam to a version beyond 1.6.6 if available. If no patch exists, restrict access to the /api/project/task/export endpoint via firewall rules or web server configuration. Validate and sanitize all inputs in the file parameter, ensuring path normalization is applied before file operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88394. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart