CVE-2026-49136
Anionex banana-slides
Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete path prefix check using os.path.startswith() without a trailing separator. Attackers can supply crafted markdown image references in user-controlled page descriptions that resolve to sibling directories whose names share the uploads folder prefix, bypassing the directory confinement check and ca...
- CVSS
- 8.7
- EPSS
- 0.42% 34.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.02