CVE-2026-71268: Thiagoralves OpenPLC v3
Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.
OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function, validate_file_path, exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program, leaving the sink unprotected.
Affected products
- Thiagoralves OpenPLC v3: any version
Published 2026-08-05. Last modified 2026-08-26.