Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53528— FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter

Quick assessment

Affected
perber leafwiki
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LeafWiki 是一款可自托管的 Wiki 系统。在版本 0.3.0 至 0.10.0 中,LeafWiki 的资源重命名功能存在路径遍历漏洞。拥有编辑权限的已认证用户可以将 LeafWiki 服务器进程可访问的文件移动到某个页面的资源目录中。这可能导致敏感本地文件(例如应用程序数据库)被作为页面资源进行下载。建议用户升级至 0.10.1 或更高版本。 为进一步加强安全防护,部署者应确保 LeafWiki 进程以最小必要权限运行,并且其文件系统访问权限仅限于应用所需目录,不得访问应用目录之外的敏感文件。在补丁实施

CVSS 8.8 · High EPSS 0.35% · P28

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery

Affected Version Matrix 1

VendorProduct Version RangeStatus
perber leafwiki >= 0.3.0, < 0.10.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53528

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter
Source: CVE Program / CVE List V5
Vulnerability Description
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset directory. This could allow sensitive local files, such as the application database, to become downloadable as page assets. Users should update to version 0.10.1 or greater. As an additional mitigation, operators should ensure that the LeafWiki process runs with the least privileges necessary and does not have filesystem access to sensitive files outside the application’s required directories. Until a patch is applied, operators may reduce risk by restricting editor access to trusted users only and by limiting the filesystem permissions of the LeafWiki process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
perber leafwiki >= 0.3.0, < 0.10.1 -

II. Public POCs for CVE-2026-53528

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7161 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-53528

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53528 (1)

Same Patch Batch · perber · 2026-08-21 · 3 CVEs total

CVE-2026-53527 8.8 HIGH LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update
CVE-2026-53529 4.8 MEDIUM LeafWiki vulnerable to stored XSS via search-result title (highlight() returns raw title i

IV. Related Vulnerabilities

V. Comments for CVE-2026-53528

No comments yet


Leave a comment