icon

We found results for “

WS-2022-0436

Date: August 19, 2025

Yapscan's report receiver server 0.18.0 up to 0.19.0 is vulnerable to path traversal and log injection. If you make use of the report receiver server (experimental), a client may be able to forge requests such that arbitrary files on the host can be overwritten (subject to permissions of the yapscan server), leading to loss of data. This is particularly problematic if you do not authenticate clients and/or run the server with elevated permissions. Version 0.19.1 contains a patch for this issue.

Language: Go

Severity Score

Severity Score

Weakness Type (CWE)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-22

Improper Output Neutralization for Logs

CWE-117

External Control of File Name or Path

CWE-73

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us