CVE-2026-19326 - CERT CVE
ID CVE-2026-19326
Sažetak A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.
Reference
CVSS
Base: 3.2
Impact: 4.9
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:L/AC:L/Au:S/C:N/I:P/A:P
Zadnje važnije ažuriranje 12-08-2026 - 20:59
Objavljeno 09-08-2026 - 03:16