Australian e-Health Research Centre Pathling是Australian e-Health Research Centre组织的一款支持健康数据整合与查询的服务器设备。 Australian e-Health Research Centre Pathling 2.0.0之前版本存在安全漏洞,该漏洞源于 端点未对file参数进行路径规范化,可能导致攻击者读取仓库中的其他文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47660 | 8.7 HIGH | Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltra |
| CVE-2026-47661 | 8.7 HIGH | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read |
| CVE-2026-47662 | 8.7 HIGH | Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning |
| CVE-2026-47663 | 8.7 HIGH | Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and c |
| CVE-2026-47664 | 8.6 HIGH | Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and wareho |
No comments yet