PT-2026-39201 · Unknown · Solidcam-Gppl-Ide
Claude Opus
·
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2026-42213
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SolidCAM-GPPL-IDE versions 1.0.0 through 1.0.1
Description
The
GpplDocumentLinkHandler resolves the filename directive in GPPL postprocessor files into clickable links. The handler accepts arbitrary absolute, relative, UNC, and subfolder paths, calling File.Exists to determine if a link should be rendered. This allows for information disclosure through path probing and NTLM hash leaks via UNC path probing.Recommendations
Update to version 1.0.2.
Exploit
Fix
Information Disclosure
SSRF
Path traversal
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solidcam-Gppl-Ide