CVE-2026-3188 is a path traversal vulnerability in feiyuchuixue sz-boot-parent up to version 1.3.2-beta, specifically within the /api/admin/common/download/templates API component. An attacker can manipulate the templateName argument to traverse directories, potentially accessing unauthorized files. Rated Medium (CVSS 4.3), this vulnerability allows remote exploitation with low attack complexity, leading to potential information disclosure (C:L). While public exploit code exists, there is no evidence of active exploitation, and community discussion is minimal. A fix is available in version 1.3.3-beta.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Feiyuchuixue | Sz-Boot-Parent | 1.3.2-betaCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.