Impact
The vulnerability resides in the resolveTargetPath function of the File Preview Service. Malicious manipulation of the file_path argument allows an attacker with local access to resolve any absolute or relative path, potentially exposing sensitive files outside the intended preview directory. This flaw is identified as a pathname traversal weakness and can be used to read arbitrary files on the host. No remote code execution or privilege escalation is afforded by the vulnerability itself.
Affected Systems
The affected product is proma‑ai Proma, versions up to and including 0.19.37. The fix is included in release 0.19.52. All other versions of Proma are presumed unaffected unless they share the same codebase without the patch.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Local access is required to exploit the flaw; therefore the risk is primarily to insiders or attackers who gain physical or local logical access to the machine running Proma. While the vulnerability allows data disclosure, it does not provide a path to remote code execution or cause denial of service. The likelihood of exploitation is modest, given the local required access, but an attacker could still prove the bug in a publicly disclosed PoC. The main concern is accidental or malicious exploitation by a privileged or compromised local user.
OpenCVE Enrichment