CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-45230

Critical · CVSS 9.1

DumbAssets — Path Traversal Arbitrary File Deletion (CWE-22)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-22

Description

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application directory and delete critical files such as server.js or package.json, causing complete denial of service.

Search profile — drives PoC discovery

Symbols POST /api/delete-filefilesToDeleteserver.jspackage.jsonDumbWareio/DumbAssets
Keywords CVE-2026-45230DumbAssetspath traversaldelete-filefilesToDeletedirectory traversalunauthenticated file deletionDumbWareio../denial of service
Versions: <= 1.0.11

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z