Voyager v1.2.7 Releaseproduct
https://github.com/the-control-group/voyager/releases/tag/v1.2.7 CVE-2020-37214
HIGH
Voyager 1.3.0 - Directory Traversal
Record summary
CVE-2020-37214 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | <= 1.3.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBVoyager 1.3.0 - Directory TraversalExploitDB exploitby NgoAnhDucNot analyzed1 file
References
6Voyager v1.3.0 Releaseproduct
https://github.com/the-control-group/voyager/releases/tag/v1.3.0 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37214 Voyager Official Homepageproduct
https://voyager.devdojo.com/ ExploitDB-47875exploit
https://www.exploit-db.com/exploits/47875 VulnCheck Advisory: Voyager 1.3.0 - Directory TraversalThird-party advisory
https://www.vulncheck.com/advisories/voyager-directory-traversal