CVE-2026-42564 - jotty·page: Unauthenticated Path Traversal leads to sensitive file disclosure and session-token reuse impact
CVE ID :CVE-2026-42564 Published : May 11, 2026, 10:22 p.m. | 43 minutes ago Description :jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is joined
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Google Detects First AI-Generated Zero-Day Exploit
- [CYBER] Privacy watchdog wraps up probe into Coupang data leak, to decide penalty as early as June
- [CYBER] Pressure mounts on Canvas as data leak extortion deadline looms
- [CYBER] Developer of education tool Canvas issues apology after hack
- [CYBER] Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
- [CYBER] Nvidia GeForce NOW data breach confirmed — but luckily most of us will be safe, here's why