CVE-2026-82460
Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.
| CWE | CWE-22 |
| Vendor | coderaiser |
| Product | cloudcmd |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for coderaiser cloudcmd
Be the first to know when new critical vulnerabilities affecting coderaiser cloudcmd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
coderaiser / cloudcmd
0 < 19.20.2
References
github.com: https://github.com/coderaiser/cloudcmd/issues/474 github.com: https://github.com/coderaiser/cloudcmd/commit/b9bdc9ed528350eeb2f9ef974c18998096fae919 github.com: https://github.com/coderaiser/cloudcmd/releases/tag/v19.20.2 github.com: https://github.com/coderaiser/cloudcmd/blob/v19.20.1/server/root.js github.com: https://github.com/coderaiser/cloudcmd vulncheck.com: https://www.vulncheck.com/advisories/cloud-commander-before-19.20.2-directory-traversal-via-rest-and-markdown
Credits
Dilipkumar Choudhary