CVE-2026-41951

HIGH

Growi - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Title source: rule
STIX 2.1

Description

Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.

References (2)

Core 2

Scores

CVSS v3 7.2
EPSS 0.0050
EPSS Percentile 38.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
GROWI, Inc./GROWI v7.5.0 and earlier
Published May 11, 2026
Tracked Since May 11, 2026