PT-2026-29477 · Sanster · Sanster Iopaint

Vuldb

+1

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-5258

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sanster IOPaint version 1.5.3
Description A path traversal issue exists in the File Manager component of Sanster IOPaint version 1.5.3, specifically within the get file function of the iopaint/file manager/file manager.py file. Manipulation of the filename argument can lead to path traversal. The exploit has been made public and is possible to be carried out remotely. The vendor was contacted but did not respond.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the iopaint/file manager/file manager.py file.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-5258

Affected Products

Sanster Iopaint