PatchSiren

yushine CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW yushine CVE published 2026-08-05

CVE-2026-18959

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T21:16:58.003Z and has not been modified since then. This CVE affects yushine InnoShop up to version 0.8.2, specifically the FileManagerController::destroyFiles function in innopacks/restapi/routes/panel-api.php, allowing path traversal. The attack may be initiated remotely. Limited details are av [truncated]