CVE-2026-61505: Rejetto HFS
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the shared folders. Exploitation is constrained to files matching a narrow naming and format pattern, limiting practical impact.
Affected products
- Rejetto HFS: from 3.0.0, before 3.2.1 (fixed in 3.2.1)
Published 2026-07-13. Last modified 2026-07-14.