vulnti.work

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query par…

High CVSS 7.5
CVECVE-2026-91144
First seen2026-09-17 23:01 UTC
Disclosed2026-09-14 22:16 UTC
Last updated2026-09-17 23:01 UTC
Channel statusauto

Summary

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD