CVE-2023-45277: Spaceapplications Yamcs

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

Affected products

Published 2023-10-19. Last modified 2026-06-17.