Fohrloop · Dash-Uploader · CVE-2026-38361
**Name of the Vulnerable Software and Affected Versions**
fohrloop dash-uploader versions 0.1.0 through 0.7.0a2
**Description**
A remote attacker can execute arbitrary code through the `Upload` function and the `max file size` parameter within the `dash uploader/httprequesthandler.py`, `dash uploader/upload.py`, and `dash uploader/configure upload.py` components.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.