PT-2026-35238 · 666Ghj · Mirofish

York Shen

·

Published

2026-04-26

·

Updated

2026-04-26

·

CVE-2026-7059

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get simulation posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of the argument Platform results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-7059

Affected Products

Mirofish