๐Ÿ” CVE Alert

CVE-2026-42598

UNKNOWN 0.0

Pode: Directory Traversal is possible on Static Routes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the contents returned. This vulnerability is fixed in 2.13.0.

CWE CWE-22
Vendor badgerati
Product pode
Published May 14, 2026
Last Updated May 14, 2026
Stay Ahead of the Next One

Get instant alerts for badgerati pode

Be the first to know when new unknown vulnerabilities affecting badgerati pode are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Badgerati / Pode
< 2.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Badgerati/Pode/security/advisories/GHSA-7rhp-w8fv-h99q github.com: https://github.com/Badgerati/Pode/issues/1667