CVE-2026-91144: Zfile-Dev Zfile
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
Affected products
- Zfile-Dev Zfile: up to and including 5.0.5
Published 2026-09-14. Last modified 2026-09-24.