Impact
WookTeam version 1.6.6 and earlier are vulnerable to a directory traversal flaw. The /api/project/task/export endpoint accepts a JSON payload, concatenates the file field directly into a storage path, and streams the resulting file using response()->download(). Because no path normalization or boundary checks are performed, an attacker can craft a payload containing ../ sequences to escape the intended storage directory and read any file readable by the web server process. This flaw enables an unauthenticated or lightly authenticated attacker to read arbitrary files on the server, compromising confidentiality and potentially gaining further foothold if sensitive configuration or credentials are exposed.
Affected Systems
All installations of WookTeam running version 1.6.6 or earlier are affected, regardless of vendor or environment, as the vulnerability resides in the core task export code shared across those releases.
Risk and Exploitability
The exploitation requires only that the attacker can send an HTTP request to the vulnerable endpoint, so the attack vector is remote and does not depend on local attacker presence. No advanced privileges are needed beyond the web server account's file permissions. Because the EPSS score is unavailable and the flaw is not listed in CISA's KEV database, the current public exploitation likelihood is uncertain, but the absence of countermeasures suggests that an attacker could easily craft and deploy a payload over the network.
OpenCVE Enrichment