CVE-2026-40163

EUVD-2026-21517
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthenticated attacker to create arbitrary directories and write a changes.json file with attacker-controlled JSON content anywhere on the server filesystem. The GET /sync/upload_finished endpoint allows an unauthenticated attacker to list arbitrary directory contents and read specific JSON files. This vulnerability is fixed in 1.4.5, 1.5.5, and 1.6.0-beta.4.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
saltcornsaltcorn
𝑥
< 1.4.5
saltcornsaltcorn
1.5.0 ≤
𝑥
< 1.5.5
saltcornsaltcorn
1.6.0:alpha0
saltcornsaltcorn
1.6.0:alpha1
saltcornsaltcorn
1.6.0:alpha10
saltcornsaltcorn
1.6.0:alpha11
saltcornsaltcorn
1.6.0:alpha12
saltcornsaltcorn
1.6.0:alpha13
saltcornsaltcorn
1.6.0:alpha14
saltcornsaltcorn
1.6.0:alpha15
saltcornsaltcorn
1.6.0:alpha16
saltcornsaltcorn
1.6.0:alpha17
saltcornsaltcorn
1.6.0:alpha2
saltcornsaltcorn
1.6.0:alpha3
saltcornsaltcorn
1.6.0:alpha4
saltcornsaltcorn
1.6.0:alpha5
saltcornsaltcorn
1.6.0:alpha6
saltcornsaltcorn
1.6.0:alpha7
saltcornsaltcorn
1.6.0:alpha8
saltcornsaltcorn
1.6.0:alpha9
saltcornsaltcorn
1.6.0:beta1
saltcornsaltcorn
1.6.0:beta2
saltcornsaltcorn
1.6.0:beta3
𝑥
= Vulnerable software versions