CVE-2026-45532: Dataease
High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.
Affected products
- Dataease Dataease: before 2.10.23 (fixed in 2.10.23)
Published 2026-08-18. Last modified 2026-09-18.