CVE-2026-33329 is a high-severity path traversal vulnerability impacting FileRise web file manager versions 1.0.1 through 3.9.x. An authenticated user with upload permissions can exploit an unsanitized parameter in the chunked upload handler to write or delete files in arbitrary directories on the server. This network-based attack has low complexity and requires low privileges, leading to high integrity and availability impacts, reflected by a CVSS score of 8.1. While no public exploits or active exploitation have been observed, the vulnerability allows for significant system compromise or denial of service. The issue has been patched in FileRise version 3.10.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.1, < 3.10.0CPE matchmatch criteria | cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.