CVE-2026-45532EPSS p41.8%
CVE-2026-45532CVE-2026-45532
Description
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.
Scoring
| EPSS | 0.52% probability of exploitation · percentile 41.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-18 |