GHSA-2wmx-vpxq-f7g7HighCVSS 7.5

WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export...

Published
October 5, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.

🔗 References (3)