Description
Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Manipulation
Action: Immediate Patch
AI Analysis

Impact

Flextype CMS versions up to 1.0.0‑alpha.3 contain a path traversal flaw in the Entries REST API. The API accepts id and new_id parameters without proper validation, allowing authenticated API token holders to craft requests that escape the intended entries directory. Attackers can read the contents of any file on the filesystem, create new files, or overwrite existing ones beyond the entries directory, potentially modifying configuration files or deploying malicious code. This vulnerability is categorized as CWE‑22 and can lead to significant confidentiality, integrity, and availability impacts if exploited.

Affected Systems

All installations of Flextype CMS up to and including version 1.0.0‑alpha.3 are affected. The vulnerability exists in the core Entries.php component of the software, impacting sites that expose the Entries REST API and issue API tokens to users. Any user or application with possession of a valid API token is vulnerable to the attack. No higher or lower versions were explicitly stated as unaffected, so the safety recommendation applies to the entire pre‑1.0.0‑alpha.3 release line.

Risk and Exploitability

The CVSS score of 7.2 denotes high severity and the EPSS score of < 1% indicates a very low historical exploitation probability. Because the flaw requires an authenticated API token, legitimate users who hold such tokens could be abused. The exposed network‑accessible Entries REST API allows remote attackers to craft authenticated requests that utilize traversal sequences in the id or new_id parameters. Though the EPSS suggests exploitation is unlikely, the high impact, remote nature, and absence from the CISA KEV catalog mean the vulnerability could be used to manipulate arbitrary files, potentially leading to code execution or defacement.

Generated by OpenCVE AI on September 17, 2026 at 18:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flextype CMS to a version that validates the id and new_id parameters and restricts file access to the entries directory.
  • If an upgrade is impossible, immediately revoke or limit all API tokens that permit file creation or modification, restricting remaining tokens to read‑only access until a patch is available.
  • Implement network‑level controls, such as firewall rules or VPN access, to limit exposure of the Entries REST API to trusted hosts or internal networks.

Generated by OpenCVE AI on September 17, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Flextype
Flextype flextype
Vendors & Products Flextype
Flextype flextype

Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.
Title Flextype CMS through 1.0.0-alpha.3 Path Traversal via Entries REST API
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Flextype Flextype
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:21.119Z

Reserved: 2026-09-14T23:08:38.870Z

Link: CVE-2026-91751

cve-icon Vulnrichment

Updated: 2026-09-15T19:06:07.587Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T01:16:54.797

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-91751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')