Description
A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Path traversal allowing remote file read
Action: Assess Impact
AI Analysis

Impact

A path traversal flaw exists in the DocController.doGetTmp function of RainyGao DocSys, enabling attackers who can modify the 'path' or 'fileName' parameters in requests to /Doc/doGetTmpFile.do to read arbitrary files on the server. This remote exploitation can expose sensitive configuration data and credentials, compromising confidentiality. The issue is identified as CWE‑22 and carries a CVSS score of 5.3, indicating moderate severity.

Affected Systems

The vulnerability affects RainyGao DocSys up to and including version 2.02.85. Any installation of the document controller component exposed through /Doc/doGetTmpFile.do is potentially susceptible.

Risk and Exploitability

With a CVSS score of 5.3 the risk is moderate, and while an EPSS score is not available, the flaw has been publicly disclosed and could be actively exploited. Attackers only need network access to the vulnerable endpoint; no local privileges are required. The vulnerability is not listed in CISA KEV, but its public disclosure and remote exploitation path emphasize the need for timely mitigation.

Generated by OpenCVE AI on October 4, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Block or restrict traffic to the /Doc/doGetTmpFile.do endpoint until a fix is available
  • Monitor the RainyGao repository and security advisories for a patch and apply the update promptly when released
  • If immediate removal is not feasible, remove or disable the endpoint from public exposure to prevent exploitation
  • Implement additional input validation or path canonicalization on the application layer or reverse proxy to reject malformed path parameters, such as disallowing '..' sequences or enforcing a strict directory whitelist

Generated by OpenCVE AI on October 4, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title RainyGao DocSys Document Controller doGetTmpFile.do DocController.doGetTmp path traversal
First Time appeared Rainygao
Rainygao docsys
Weaknesses CWE-22
CPEs cpe:2.3:a:rainygao:docsys:*:*:*:*:*:*:*:*
Vendors & Products Rainygao
Rainygao docsys
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T12:45:23.148Z

Reserved: 2026-10-03T19:42:49.393Z

Link: CVE-2026-105157

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T15:16:30.947

Modified: 2026-10-04T15:16:30.947

Link: CVE-2026-105157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T15:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')