CVE-2025-26260
12.03.2025, 16:15
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References