CVE-2026-7059

MEDIUM

666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal

Title source: cna
STIX 2.1

Description

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of the argument Platform results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-359632 | 666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal
https://vuldb.com/vuln/359632
Signature, Permissions Required signature permissions-required
VDB-359632 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/359632/cti
Third Party Advisory third-party-advisory
Submit #798605 | 666ghj MiroFish 0.1.2 Arbitrary SQLite Database Read
https://vuldb.com/submit/798605
Exploit exploit issue-tracking
https://github.com/666ghj/MiroFish/issues/489

Scores

CVSS v3 5.3
EPSS 0.0044
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (3)
666ghj/MiroFish 0.1.0
666ghj/MiroFish 0.1.1
666ghj/MiroFish 0.1.2
Published Apr 26, 2026
Tracked Since Apr 27, 2026