Description
WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary file read via directory traversal
Action: Apply Patch
AI Analysis

Impact

WookTeam version 1.6.6 and earlier are vulnerable to a directory traversal flaw. The /api/project/task/export endpoint accepts a JSON payload, concatenates the file field directly into a storage path, and streams the resulting file using response()->download(). Because no path normalization or boundary checks are performed, an attacker can craft a payload containing ../ sequences to escape the intended storage directory and read any file readable by the web server process. This flaw enables an unauthenticated or lightly authenticated attacker to read arbitrary files on the server, compromising confidentiality and potentially gaining further foothold if sensitive configuration or credentials are exposed.

Affected Systems

All installations of WookTeam running version 1.6.6 or earlier are affected, regardless of vendor or environment, as the vulnerability resides in the core task export code shared across those releases.

Risk and Exploitability

The exploitation requires only that the attacker can send an HTTP request to the vulnerable endpoint, so the attack vector is remote and does not depend on local attacker presence. No advanced privileges are needed beyond the web server account's file permissions. Because the EPSS score is unavailable and the flaw is not listed in CISA's KEV database, the current public exploitation likelihood is uncertain, but the absence of countermeasures suggests that an attacker could easily craft and deploy a payload over the network.

Generated by OpenCVE AI on October 5, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a WookTeam release that addresses the directory traversal flaw (e.g., v1.6.7 or later).
  • If an upgrade is not yet possible, restrict or disable access to the /api/project/task/export endpoint so that only trusted administrators can invoke it.
  • Implement server‑side validation that sanitizes the file field and normalizes the path before concatenation to prevent traversal,

Generated by OpenCVE AI on October 5, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Title Directory Traversal in WookTeam v1.6.6 and Earlier
Weaknesses CWE-22

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T14:22:29.647Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88394

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T15:17:22.997

Modified: 2026-10-05T15:17:22.997

Link: CVE-2026-88394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T15:30:20Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')