No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sanster
Sanster iopaint |
|
| Vendors & Products |
Sanster
Sanster iopaint |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the argument filename results in path traversal. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Sanster IOPaint File Manager file_manager.py _get_file path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-01T19:05:54.855Z
Reserved: 2026-03-31T16:20:10.685Z
Link: CVE-2026-5258
Updated: 2026-04-01T19:05:51.521Z
Status : Awaiting Analysis
Published: 2026-04-01T07:16:02.930
Modified: 2026-04-01T14:23:37.727
Link: CVE-2026-5258
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:18:03Z