CVE-2026-45230CRITICAL 9.1EPSS p45.2%

CVE-2026-45230CVE-2026-45230

Description

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application directory and delete critical files such as server.js or package.json, causing complete denial of service.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS0.63% probability of exploitation · percentile 45.2% · 2026-06-18T12:00:27Z
Published2026-05-18
Last modified2026-05-18

Underlying weaknesses· 1

CWE-22

References

  1. https://github.com/DumbWareio/DumbAssets/pull/136
  2. https://www.vulncheck.com/advisories/dumbassets-path-traversal-file-deletion-via-api-delete-file

1

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-5027
CVE
CVE-2026-36726
CVE
CVE-2025-24891
CVE
CVE-2025-65879
CVE
CVE-2026-35214
CVE
CVE-2026-2953
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.