CVE-2026-5013 identifies a path traversal vulnerability in elecV2 elecV2P versions up to 3.8.3, specifically impacting the `path.join` function within the `/store/:key` file. This medium-severity issue (CVSS 5.3) can be exploited remotely with low attack complexity, potentially allowing an attacker to access unauthorized files. Although an exploit has been publicly disclosed, there is currently no evidence of active exploitation in the wild, nor are specific exploit tools like Metasploit or Nuclei available. Community and media attention surrounding this vulnerability remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ElecV2 | ElecV2P | 3.8.0, 3.8.1, 3.8.2, 3.8.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.