External Control of File Name or Path in the upload API...
Critical severity
Unreviewed
Published
Aug 21, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Description
Published by the National Vulnerability Database
Aug 21, 2026
Published to the GitHub Advisory Database
Aug 21, 2026
Last updated
Aug 21, 2026
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
References