CVE-2026-71805
An attacker can upload any file to the server and place it outside the intended directory, potentially allowing them to execute malicious code. The flaw exists in LZ-litchi 1.0.0 and is triggered by the directory parameter in a file upload request. It is rated critical due to the ability to write arbitrary files without authentication.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
LZ-litchi 1.0.0 (no other versions listed).
Real-world impact
An attacker could place malicious files on the server, potentially leading to remote code execution, data theft, or service disruption.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network with no authentication or user interaction, and it allows complete compromise of confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources