DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Affected products
DTStack · TaierReferences
https://github.com/DTStack/Taier/https://github.com/DTStack/Taier/commit/ec8c59c76aceb04ab3080543ab2d9c6a4b674729https://github.com/DTStack/Taier/issues/1204https://github.com/DTStack/Taier/releases/tag/v1.5.0https://vuldb.com/cve/CVE-2026-19763https://vuldb.com/submit/868967https://vuldb.com/vuln/389666https://vuldb.com/vuln/389666/cti