CVE-2026-38360

Critical severity, CVSS 9.8. EPSS: 6.1% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components.

Published 2026-05-08. Last modified 2026-06-17.