PatchSiren

kekingcn CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kekingcn CVE published 2026-08-11

CVE-2026-73244

kkFileView, a universal file online preview project based on Spring Boot, has a vulnerability prior to version 5.0.1. The unauthenticated POST /listFiles endpoint allows directory enumeration outside the intended root directory due to the lack of confinement in the FileController#getFiles method. This issue is fixed in version 5.0.1. Defenders should verify exposure, prioritize remediation, and monitor fo [truncated]

MEDIUM kekingcn CVE published 2026-08-11

CVE-2026-73243

CVE-2026-73243 is a vulnerability in kkFileView, a universal file online preview project based on Spring Boot. The unauthenticated GET /addTask endpoint allows an attacker to fetch a URL of their choice, potentially leading to security issues such as data exposure or integrity issues. Defenders should prioritize verifying exposure and applying the patch to prevent potential security issues. The vulnerabil [truncated]