PatchSiren

yangzongzhuan CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW yangzongzhuan CVE published 2026-08-19

CVE-2026-76576

A path traversal vulnerability was found in RuoYi-Vue up to 3.9.2, impacting the fileDownload/resourceDownload function in CommonController.java. This allows remote manipulation of the fileName/resource argument, potentially leading to unauthorized file access. The vulnerability has a CVSS score of 2.1 and is classified as LOW severity. Teams using RuoYi-Vue up to 3.9.2 should assess and mitigate this vul [truncated]

MEDIUM yangzongzhuan CVE published 2026-05-24

CVE-2026-9374

A vulnerability in yangzongzhuan RuoYi-Vue up to version 3.9.2 allows remote attackers to perform unrestricted file uploads via the FileUploadUtils.upload function in the /common/upload endpoint. The vulnerability stems from improper access control (CWE-284) and unrestricted upload of file with dangerous type (CWE-434), enabling attackers to upload potentially malicious files without adequate validation. [truncated]