← back
CVE-2026-72569criticalCWE-22

cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1
exploitation probability
observed exploitation
nono source reports it
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H