CVE-2026-45230
Critical · CVSS 9.1DumbAssets — Path Traversal Arbitrary File Deletion (CWE-22)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-22
Description
DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application directory and delete critical files such as server.js or package.json, causing complete denial of service.
Search profile — drives PoC discovery
Symbols POST /api/delete-filefilesToDeleteserver.jspackage.jsonDumbWareio/DumbAssets
Keywords CVE-2026-45230DumbAssetspath traversaldelete-filefilesToDeletedirectory traversalunauthenticated file deletionDumbWareio../denial of service
Versions: <= 1.0.11
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z