HIGH
crivion
CVE published 2026-09-26
CVE-2026-100520
CVE-2026-100520 is a path traversal vulnerability in Laranode versions before 1.2.1. Authenticated users can write arbitrary files outside their home directory by supplying directory traversal sequences in the path parameter of the POST /filemanager/upload-file endpoint. This can lead to writing PHP files into other tenants' web roots and executing code as those tenants.