No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 30 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hkuds
Hkuds deepcode |
|
| Vendors & Products |
Hkuds
Hkuds deepcode |
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to traverse outside FRONTEND_DIST and exposing sensitive files such as SSH private keys, TLS certificates, and application secrets with a single HTTP request. | |
| Title | DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-30T02:12:30.583Z
Reserved: 2026-03-16T18:11:41.758Z
Link: CVE-2026-32847
Updated: 2026-05-30T02:12:26.456Z
Status : Awaiting Analysis
Published: 2026-05-28T20:16:22.613
Modified: 2026-05-29T16:19:35.753
Link: CVE-2026-32847
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:47:50Z