Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-38360: fohrloop dash-uploader allows remote code execution

Exploitation likelihood: 14%
CVE-2026-38360
Summary

The fohrloop dash-uploader, used to upload files, has a security flaw that lets an attacker run unauthorized code on a server. This could allow an attacker to access sensitive data or disrupt the server. To stay safe, update the dash-uploader to the latest version.

Original title
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestH...
Original description
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components
Vulnerability type
CWE-22 Path Traversal
Published: 8 May 2026 · Updated: 23 May 2026 · First seen: 8 May 2026