CVE-2026-45532: Dataease

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.

Affected products

  • Dataease Dataease: before 2.10.23 (fixed in 2.10.23)

Published 2026-08-18. Last modified 2026-09-18.