fohrloop dash-uploader v0.1.0 through v0.7.0a2 contains a directory traversal vulnerability caused by improper handling in dash_uploader/httprequesthandler.py components, letting remote attackers execute arbitrary code, exploit requires no special privileges.
id: CVE-2026-38360
info:
name: dash-uploader 0.1.0 - 0.7.0a2 - Unauthenticated Arbitrary File Wri
...