OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vulnerability is fixed in 5.8.1.
References
| Link | Resource |
|---|---|
| https://github.com/orangehrm/orangehrm/security/advisories/GHSA-xq24-qv66-9v3m | Vendor Advisory |
Configurations
History
09 Apr 2026, 16:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/orangehrm/orangehrm/security/advisories/GHSA-xq24-qv66-9v3m - Vendor Advisory | |
| First Time |
Orangehrm
Orangehrm orangehrm |
|
| CPE | cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
07 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 19:16
Updated : 2026-06-17 10:41
NVD link : CVE-2026-39345
Mitre link : CVE-2026-39345
CVE.ORG link : CVE-2026-39345
JSON object : View
Products Affected
orangehrm
- orangehrm
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
