CVE-2021-41185

HIGH

Mycodo < 8.12.7 - Path Traversal via File Download Endpoint

Title source: llm
STIX 2.1

Description

Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a workaround, users may manually apply the changes from the fix commit.

References (4)

Core 4
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/kizniche/Mycodo/security/advisories/GHSA-252r-94ph-m229
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/kizniche/Mycodo/issues/1105
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/kizniche/Mycodo/releases/tag/v8.12.7

Scores

CVSS v3 8.8
EPSS 0.0138
EPSS Percentile 68.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
mycodo_project/mycodo < 8.12.7
Published Oct 26, 2021
Tracked Since Feb 18, 2026