Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device.
References
| Link | Resource |
|---|---|
| https://apps.apple.com/us/app/owlfiles-file-manager/id510282524 | Product |
| https://www.exploit-db.com/exploits/51036 | Exploit |
| https://www.skyjos.com/ | Product |
| https://www.vulncheck.com/advisories/owlfiles-file-manager-path-traversal | Third Party Advisory |
| https://www.exploit-db.com/exploits/51036 | Exploit |
Configurations
Configuration 1 (hide)
| AND |
|
History
29 Jan 2026, 00:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://apps.apple.com/us/app/owlfiles-file-manager/id510282524 - Product | |
| References | () https://www.exploit-db.com/exploits/51036 - Exploit | |
| References | () https://www.skyjos.com/ - Product | |
| References | () https://www.vulncheck.com/advisories/owlfiles-file-manager-path-traversal - Third Party Advisory | |
| First Time |
Apple tvos
Skyjos owlfiles Apple ipados Skyjos Apple iphone Os Apple visionos Apple macos Apple |
|
| CPE | cpe:2.3:o:apple:ipados:-:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:-:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:* cpe:2.3:a:skyjos:owlfiles:12.0.1:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:-:*:*:*:*:*:*:* |
14 Jan 2026, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/51036 - |
13 Jan 2026, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 23:15
Updated : 2026-01-29 00:43
NVD link : CVE-2022-50890
Mitre link : CVE-2022-50890
CVE.ORG link : CVE-2022-50890
JSON object : View
Products Affected
skyjos
- owlfiles
apple
- iphone_os
- visionos
- tvos
- ipados
- macos
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
