OVERVIEW CVE-2026-35613 is a path traversal vulnerability in coursevault-preview versions prior to 0.1.1, a utility designed for previewing course material files from configured directories. The vulnerability exists in the resolveSafe utility function, which uses flawed boundary checking logic that fails to properly enforce directory boundaries. An attacker who controls the relativePath argument can read files outside the intended baseDir when sibling directories share the same string prefix as the configured directory. SEVERITY This vulnerability has a CVSS 3.1 score of 5.1 (Medium), indicating moderate risk. The attack vector is local, requiring attacker access to the system, with high attack complexity. The vulnerability requires specific conditions—such as the presence of a sibling directory with a matching prefix—to be successfully exploited. The primary impact is confidentiality, as unauthorized file disclosure is possible, while integrity and availability remain unaffected. The EPSS score of 0.0002 indicates this vulnerability is exploited less frequently than the vast majority of CVEs. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, remains inactive on the Hot List, and exhibits negligible community attention based on EPSS metrics. No publicly available exploit code has been widely distributed. Organizations using coursevault-preview should upgrade to version 0.1.1 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.1CPE matchmatch criteria | cpe:2.3:a:moritzmyrz:coursevault-preview:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.