CVE-2018-16836: Rubedo Project Rubedo

Critical severity, CVSS 9.8. EPSS: 61.4% chance of exploitation in the next 30 days.

Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.

Affected products

Published 2018-09-11. Last modified 2026-06-17.