Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-100520: Laranode before 1.2.1 lets users place files anywhere

CVE-2026-100520 · published 2 days ago
Summary

Versions of Laranode older than 1.2.1 let a signed‑in user upload files to locations outside their own folder. By tricking the system with special path strings, an attacker could drop a script into another tenant’s website and run code as that tenant. Upgrade to version 1.2.1 or later, or apply the vendor’s patch, to stop this behavior.

What to do
  • Update crivion laranode to version 1.2.1 or later.
Affected software
VendorProductAffected versions
crivion laranode < 1.2.1
Original advisory text
Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
Severity
9.4 Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published26 Sep 2026
Updated27 Sep 2026
First seen26 Sep 2026
Sources
CVE-2026-100520 · MITRE
Track software like this
Free during beta