kkFileView, a universal file online preview project based on Spring Boot, has a vulnerability prior to version 5.0.1. The unauthenticated POST /listFiles endpoint allows directory enumeration outside the intended root directory due to the lack of confinement in the FileController#getFiles method. This issue is fixed in version 5.0.1. Defenders should verify exposure, prioritize remediation, and monitor fo [truncated]
CVE-2026-73243 is a vulnerability in kkFileView, a universal file online preview project based on Spring Boot. The unauthenticated GET /addTask endpoint allows an attacker to fetch a URL of their choice, potentially leading to security issues such as data exposure or integrity issues. Defenders should prioritize verifying exposure and applying the patch to prevent potential security issues. The vulnerabil [truncated]