PT-2026-25565 · Jawherkl · Node-Api-Postgres

Vuldb

+1

·

Published

2026-03-15

·

Updated

2026-03-16

·

CVE-2026-4191

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JawherKl node-api-postgres versions up to 2.5
Description A flaw exists in the Profile Picture Handler component of JawherKl node-api-postgres. Specifically, the path.extname function within the index.js file is susceptible to manipulation, leading to unrestricted file upload. This issue can be exploited remotely.
Recommendations Versions prior to 2.5 should be used.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-4191

Affected Products

Node-Api-Postgres