CVE-2026-55631EPSS p37.7%

CVE-2026-55631CVE-2026-55631

Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record is later deleted, the backend concatenates that stored value with the font storage directory and passes it to FileUtils.deleteFile() without path traversal sanitization, allowing deletion of arbitrary writable files in the application container. This issue is fixed in version 2.10.24.

Scoring

EPSS0.46% probability of exploitation · percentile 37.7% · 2026-10-06T12:00:23Z
Last modified2026-07-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.