๐Ÿ” CVE Alert

CVE-2026-19054

MEDIUM 5.3

Lspace-io lspace-server Repositories File API repository.ts deleteFile path traversal

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. Performing a manipulation of the argument filePath results in path traversal. The attack is only possible with local access. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-22
Vendor lspace-io
Product lspace-server
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for lspace-io lspace-server

Be the first to know when new medium vulnerabilities affecting lspace-io lspace-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Lspace-io / lspace-server
79f02fe5aa8970b210a6a05cf097155f8d9ffd71

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/386512 vuldb.com: https://vuldb.com/vuln/386512/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19054 vuldb.com: https://vuldb.com/submit/863836 github.com: https://github.com/Lspace-io/lspace-server/issues/3 github.com: https://github.com/Lspace-io/lspace-server/

Credits

๐Ÿ” gongyanyu (VulDB User) VulDB CNA Team