CVE-2026-42598: Badgerati Pode
Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the contents returned. This vulnerability is fixed in 2.13.0.
Affected products
- Badgerati Pode: before 2.13.0 (fixed in 2.13.0)
Published 2026-05-14. Last modified 2026-06-17.