CVE-2026-58192
HIGHAppium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
Title source: cnaDescription
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to escape the storage root with ../ sequences and recursively delete arbitrary writable files or directories. This issue is fixed in version 1.1.6.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/appium/appium/security/advisories/GHSA-jwgx-mp9m-jwcr
X_Refsource_Misc x_refsource_misc
https://github.com/appium/appium/pull/22362
X_Refsource_Misc x_refsource_misc
https://github.com/appium/appium/commit/5fee01752f2782e96fbe64fd13520b433d4a7535
X_Refsource_Misc x_refsource_misc
https://github.com/appium/appium/releases/tag/%40appium/storage-plugin%401.1.6
Scores
CVSS v3
8.6
EPSS
0.0034
EPSS Percentile
27.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
CWE-73
Status
published
Products (1)
appium/appium
< 1.1.6
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026