CVE-2026-45532
DataEase has a Path Traversal Vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.
| CWE | CWE-22 |
| Vendor | dataease |
| Product | dataease |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for dataease dataease
Be the first to know when new unknown vulnerabilities affecting dataease dataease are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
dataease / dataease
< 2.10.23