PT-2026-44488 · Hkuds · Deepcode

Yu Sun

·

Published

2026-05-28

·

Updated

2026-06-03

·

CVE-2026-32847

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DeepCode versions prior to commit c991dc2
Description A path traversal issue exists in the SPA catch-all route within new ui/backend/main.py. Unauthenticated attackers can read arbitrary files by providing percent-encoded path segments to the 'GET /{full path:path}' endpoint. By encoding slashes as %2F and dots as %2E%2E, the Starlette path normalization is bypassed, allowing the joined path to move outside the FRONTEND DIST directory. This can expose sensitive data, including SSH private keys, TLS certificates, and application secrets, via a single HTTP request.
Recommendations Update to a version containing commit c991dc2 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32847

Affected Products

Deepcode