CVE-2026-53519
CRITICALNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Title source: cnaExploitation Summary
EIP tracks 2 public exploits for CVE-2026-53519. PoCs published by Unclecheng-li, tar-xz.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2026-53519, which leverages path traversal to retrieve sensitive files (config.yaml and sqlite.db) and forges a JWT token to achieve admin authentication bypass in Nezha Monitoring Dashboard.
Description
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.HasPrefix, not a path-segment match, so the input /dashboard../data/config.yaml is accepted; strings.TrimPrefix leaves ../data/config.yaml; and path.Join("admin-dist", "../data/config.yaml") normalizes to data/config.yaml — which os.Stat finds and http.ServeFile returns. No authentication required. This issue has been patched in version 2.0.13.
Exploits (2)
The repository contains a functional Python exploit for CVE-2026-53519, which leverages path traversal to retrieve sensitive files (config.yaml and sqlite.db) and forges a JWT token to achieve admin authentication bypass in Nezha Monitoring Dashboard.
This repository contains a functional exploit for CVE-2026-53519, which leverages path traversal in Nezha Dashboard to extract sensitive files (e.g., JWT secret key) and forge administrative tokens. The PoC automates the entire exploit chain, including secret extraction, database access, and token forgery.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N