Description
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.
Published: 2026-05-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is in Casdoor’s Local File System storage provider, where inadequate path sanitization allows an authenticated attacker with administrative privileges to exploit a path traversal vulnerability. This attack can create or overwrite any file on the host filesystem, breaking the application’s sandbox and giving the attacker arbitrary file write capability. The primary impact is the ability to tamper with or replace critical files, potentially compromising the integrity and confidentiality of the system.

Affected Systems

Casdoor, specifically the Casdoor implementation that uses the Local File System storage provider. No version‑specific details are supplied, so all deployments that employ this storage provider are potentially vulnerable until a vendor fix is released. Administrators should verify whether their environment uses the affected component.

Risk and Exploitability

The vulnerability requires authentication with administrative privileges, limiting the attacker to users who already have legitimate access, which constrains the attack surface. The CVSS score is 5.9, and the EPSS is below 1%, and it is not listed in CISA KEV, indicating a lower probability of exploitation. Nevertheless, if exploited, the arbitrary file write could lead to integrity violations or code execution. The risk is moderate for environments where administrative accounts are accessible or the storage provider is exposed to potentially compromised users.

Generated by OpenCVE AI on May 13, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade to the latest Casdoor release that addresses the path traversal in the Local File System storage provider.
  • If a patch is not yet available, restrict administrative privileges and enforce least privilege, ensuring only trusted users have access to the affected component.
  • Consider disabling the Local File System storage provider or switching to a sandboxed storage solution if the feature is not required.

Generated by OpenCVE AI on May 13, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Casbin
Casbin casdoor
CPEs cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:*
Vendors & Products Casbin
Casbin casdoor

Wed, 13 May 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-22

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-22

Wed, 13 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Casdoor
Casdoor casdoor
Vendors & Products Casdoor
Casdoor casdoor

Mon, 11 May 2026 18:30:00 +0000

Type Values Removed Values Added
References

Mon, 11 May 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-22

Mon, 11 May 2026 15:30:00 +0000

Type Values Removed Values Added
Description An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.
Title CVE-2026-6815
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-05-13T12:33:15.243Z

Reserved: 2026-04-21T18:50:35.842Z

Link: CVE-2026-6815

cve-icon Vulnrichment

Updated: 2026-05-11T16:53:24.656Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T16:17:37.257

Modified: 2026-06-01T16:38:43.600

Link: CVE-2026-6815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T18:45:36Z

Weaknesses