CVE-2020-36559: Aahframework Aah

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

Affected products

Published 2022-12-27. Last modified 2026-06-17.