OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-88394

HIGH · CVSS 7.5 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

WookTeam versions 1.6.6 and earlier are susceptible to a directory traversal vulnerability that allows an attacker to download arbitrary files from the server by exploiting the project task export endpoint with a specially crafted JSON payload. This flaw arises from the lack of path normalization and boundary checks, enabling attackers to escape the designated storage directory and access any file the web server can read. Organizations using affected versions should prioritize remediation to prevent unauthorized data access and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88394
Severity
HIGH
CVSS
7.5
EPSS
0.21%

Original NVD Description

WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.