HarborGuard / CVE
Back to search
HIGHCVE-2026-45230Published Modified CNA VulnCheck

CVE-2026-45230: DumbAssets 1.0.11 Path Traversal File Deletion via /api/delete-file

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application directory and delete critical files such as server.js or package.json, causing complete denial of service.

Metrics

CVSS v4.0
8.8
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • DumbWareio / DumbAssets
    ≤ 1.0.11
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N