MEDIUM
cefsharp
CVE published 2026-08-18
CVE-2026-48796
A path traversal vulnerability in CefSharp, a .NET bindings library for the Chromium Embedded Framework, allows attackers to serve local files outside the intended root directory when an embedded browser requests a crafted URL. This issue affects applications using FolderSchemeHandlerFactory for custom schemes or HTTP/HTTPS schemes. The vulnerability is fixed in version 148.0.90.