CVE-2025-26260

HIGH

Plenti <= 0.7.16 - Remote Code Execution via .svelte File Upload

Title source: llm
STIX 2.1

Description

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.

Scores

CVSS v3 8.8
EPSS 0.0070
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
plenti/plenti < 0.7.17
plentico/plenti 0 - 0.7.17Go
Published Mar 12, 2025
Tracked Since Feb 18, 2026