CVE-2026-30580

File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:leefish:file_thingie:2.5.7:*:*:*:*:*:*:*

History

01 Apr 2026, 19:01

Type Values Removed Values Added
Summary
  • (es) File Thingie 2.5.7 es vulnerable a Salto de Directorio. Un usuario malintencionado puede aprovechar la funcionalidad 'crear carpeta desde url' de la aplicación para leer archivos arbitrarios en el sistema objetivo.
First Time Leefish
Leefish file Thingie
CPE cpe:2.3:a:leefish:file_thingie:2.5.7:*:*:*:*:*:*:*
References () https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-30580 - () https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-30580 - Third Party Advisory
References () https://github.com/leefish/filethingie - () https://github.com/leefish/filethingie - Product

23 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

20 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 18:16

Updated : 2026-04-01 19:01


NVD link : CVE-2026-30580

Mitre link : CVE-2026-30580

CVE.ORG link : CVE-2026-30580


JSON object : View

Products Affected

leefish

  • file_thingie
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')