CVE-2026-52349

HIGH

MenyooSP < 729aa48 - Local Code Execution via Directory Traversal in File Management

Title source: llm
STIX 2.1

Description

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions save/folder/rename functionality, PedComponentChanger create folder/createfile/rename functionality.

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Published Jul 20, 2026
Tracked Since Jul 20, 2026