CVE-2026-71805
—Unauthenticated Arbitrary File Upload and Path Traversal in LZ-litchi 1.0.0
LZ-litchi 1.0.0 contains an unauthenticated arbitrary file upload flaw with path traversal (CWE-434), rated critical at CVSS 9.8. Attackers trigger it by sending a POST request to /app-api/infra/file/upload and controlling the directory parameter, which causes uploaded files to be written outside the intended storage directory. Successful exploitation gives a remote, unauthenticated attacker arbitrary file-write capability on the server, which can be used to plant webshells or overwrite files and may lead to remote code execution depending on where files can be placed and how the application runs. Any deployment of LZ-litchi 1.0.0 with the upload endpoint reachable over the network is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Operators running LZ-litchi 1.0.0 should upgrade to a patched release as soon as one is published (no fixed version is identified in the available data) and restrict network access to POST /app-api/infra/file/upload in the meantime. Audit the server for files written outside the intended upload storage directory and check whether any uploaded content has been executed or incorporated by the application.
| LZ-litchi | 1.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app-api/infra/file/upload.
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.