Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 22 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Mothra Default File Path Bypass in HTML Upload Forms | |
| First Time appeared |
9front
9front 9front |
|
| Weaknesses | CWE-22 | |
| Vendors & Products |
9front
9front 9front |
Fri, 22 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element. | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: 9front
Published:
Updated: 2026-05-22T02:57:35.162Z
Reserved: 2026-05-19T21:39:13.119Z
Link: CVE-2026-9053
No data.
Status : Received
Published: 2026-05-22T04:16:28.430
Modified: 2026-05-22T04:16:28.430
Link: CVE-2026-9053
No data.
OpenCVE Enrichment
Updated: 2026-05-22T04:30:25Z
Weaknesses