๐Ÿ” CVE Alert

CVE-2026-45532

UNKNOWN 0.0

DataEase has a Path Traversal Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.

CWE CWE-22
Vendor dataease
Product dataease
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for dataease dataease

Be the first to know when new unknown vulnerabilities affecting dataease dataease are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dataease / dataease
< 2.10.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dataease/dataease/security/advisories/GHSA-2mqc-w4hm-f3p9 github.com: https://github.com/dataease/dataease/releases/tag/v2.10.23