CVE-2026-55631
HIGHDataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management
Title source: cnaDescription
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record is later deleted, the backend concatenates that stored value with the font storage directory and passes it to FileUtils.deleteFile() without path traversal sanitization, allowing deletion of arbitrary writable files in the application container. This issue is fixed in version 2.10.24.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/dataease/dataease/security/advisories/GHSA-r99p-w8fc-93g6
X_Refsource_Misc x_refsource_misc
https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc
X_Refsource_Misc x_refsource_misc
https://github.com/dataease/dataease/releases/tag/v2.10.24
Scores
CVSS v4
7.2
EPSS
0.0031
EPSS Percentile
23.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
dataease/dataease
< 2.10.24
Published
Jul 07, 2026
Tracked Since
Jul 08, 2026