PT-2026-39201 · Unknown · Solidcam-Gppl-Ide

Claude Opus

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-42213

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SolidCAM-GPPL-IDE versions 1.0.0 through 1.0.1
Description The GpplDocumentLinkHandler resolves the filename directive in GPPL postprocessor files into clickable links. The handler accepts arbitrary absolute, relative, UNC, and subfolder paths, calling File.Exists to determine if a link should be rendered. This allows for information disclosure through path probing and NTLM hash leaks via UNC path probing.
Recommendations Update to version 1.0.2.

Exploit

Fix

Information Disclosure

SSRF

Path traversal

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-42213

Affected Products

Solidcam-Gppl-Ide