HarborGuard / CVE
Back to search
HIGHCVE-2026-41951Published Modified CNA jpcert

CVE-2026-41951: Path traversal vulnerability exists in GROWI v7

Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.

Metrics

CVSS v4.0
8.6
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • GROWI, Inc. / GROWI
    v7.5.0 and earlier
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-41951: Path traversal vulnerability exists in GROWI v7 | HarborGuard CVE