CVE-2026-59510
ail-project ail-framework
AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside th...
- CVSS
- 7.1
- EPSS
- 0.37% 29.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.06