CVE Explorer
CVE-2026-31817
OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk. The filename used for these log files is constructed in part from the user-supplied UniqueTrackingId field in the StartAction API request. This value is not validated or sanitized before being used in a file path, allowing an attacker to use directory traversal sequences (e.g., ../../../) to write files to arbitrary lo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"OliveTin","vendor":"OliveTin","versions":[{"status":"affected","version":"< 3000.11.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:06374ad6d3fad1f00d9e980637f70ef1451cb7c278935a8a9680cc1a07e270f9 · sha256:7ab3b7270805f222… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:06374ad6d3fad1f00d9e980637f70ef1451cb7c278935a8a9680cc1a07e270f9 · sha256:7ab3b7270805f222… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:06374ad6d3fad1f00d9e980637f70ef1451cb7c278935a8a9680cc1a07e270f9 · sha256:7ab3b7270805f222… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/OliveTin/OliveTin/security/advisories/GHSA-364q-w7vh-vhpc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OliveTin/OliveTin/security/advisories/GHSA-364q-w7vh-vhpc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:06374ad6d3fad1f00d9e980637f70ef1451cb7c278935a8a9680cc1a07e270f9 · sha256:7ab3b7270805f222… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.