CVE-2026-38360
9.8
CRITICAL · CVSS 3.1 · EPSS 6.1% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.14% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-05-08 |
| Last modified | 2026-06-17 |
References
- https://github.com/a1ohadance/CVE-2026-38360
- https://github.com/advisories/GHSA-3rf6-x59v-5jfv
- https://github.com/fohrloop/dash-uploader
- https://github.com/fohrloop/dash-uploader/blob/dev/dash_uploader/httprequesthandler.py
- https://github.com/fohrloop/dash-uploader/blob/stable/dash_uploader/httprequesthandler.py
- https://github.com/fohrloop/dash-uploader/issues/153
- https://github.com/github/advisory-database/pull/7635
- https://pypi.org/project/dash-uploader/
→ the Explorer · watch your stack · NVD