CVE-2016-10528: Restafary Project Restafary

Medium severity, CVSS 4.9. EPSS: 1.2% chance of exploitation in the next 30 days.

restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.

Affected products

Published 2018-05-31. Last modified 2026-06-17.