Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-100520: Laranode before 1.2.1 lets users place files anywhere
CVE-2026-100520 · published 2 days ago
Summary
Versions of Laranode older than 1.2.1 let a signed‑in user upload files to locations outside their own folder. By tricking the system with special path strings, an attacker could drop a script into another tenant’s website and run code as that tenant. Upgrade to version 1.2.1 or later, or apply the vendor’s patch, to stop this behavior.
What to do
- Update crivion laranode to version 1.2.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| crivion | laranode | < 1.2.1 |
Original advisory text
Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
References
- https://github.com/crivion/laranode Product
- https://github.com/crivion/laranode/blob/v1.2/app/Actions/Filemanager/UploadFile... Third Party Advisory
- https://github.com/crivion/laranode/commit/5c2b18ae99caf77a6fb6cc5c0ab66562bd673... Patch
- https://github.com/crivion/laranode/pull/21 Patch
- https://github.com/crivion/laranode/releases/tag/v1.2.1 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-1005... Vendor Advisory
- https://github.com/crivion/laranode/security/advisories/GHSA-34h2-2696-vfvr Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-100520 Vendor Advisory
- https://www.vulncheck.com/advisories/laranode-before-1.2.1-path-traversal-in-fil... Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published26 Sep 2026
Updated27 Sep 2026
First seen26 Sep 2026
Sources
CVE-2026-100520 · NVD
CVE-2026-100520 · MITRE
CVE-2026-100520 · OSV
GHSA-34h2-2696-vfvr · GHSA
Track software like this
Free during beta