WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in WookTeam v1.6.6 and Earlier | |
| Weaknesses | CWE-22 |
Mon, 05 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-05T14:22:29.647Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88394
No data.
Status : Received
Published: 2026-10-05T15:17:22.997
Modified: 2026-10-05T15:17:22.997
Link: CVE-2026-88394
No data.
OpenCVE Enrichment
Updated: 2026-10-05T15:30:20Z
Weaknesses