Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Talishar: User Can Access Unauthorized Game Files

CVE-2026-28429
Summary

A flaw in the Talishar game allows an attacker to access files outside the intended game area. This can happen when the game's data is improperly processed, potentially leading to sensitive information being exposed. To fix this, the developers have updated the game with a security patch.

Original title
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified in the gameName parameter. While the application's primary entry points implem...
Original description
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified in the gameName parameter. While the application's primary entry points implement input validation, the ParseGamestate.php component can be accessed directly as a standalone script. In this scenario, the absence of internal sanitization allows for directory traversal sequences (e.g., ../) to be processed, potentially leading to unauthorized file access. This issue has been patched in commit 6be3871.
nvd CVSS3.1 7.5
Vulnerability type
CWE-22 Path Traversal
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026