Junglewise Threat Intelligence

CVE-2026-11470: hs-web hsweb-framework path traversal in File Upload

CVE-2026-11470 · Severity: medium · CVSS 6.3 · Published 2026-06-08

Vendors: Maven.

Executive brief

hsweb-framework is a Java-based development framework used to build enterprise applications. A security flaw in its file upload component allows an attacker to bypass directory restrictions and save files to unauthorized locations on the server. This could lead to the overwriting of critical system files, potentially resulting in a complete system takeover or service disruption.

Technical details

A path traversal vulnerability exists in hsweb-framework up to version 5.0.1 within the File Upload component. The flaw is located in the `FileUploadProperties.java` file, specifically where the `filename` argument is processed without sufficient validation. By using 'dot-dot-slash' (`../`) sequences in the filename parameter during a multipart POST request to the `/file/static` endpoint, a remote authenticated attacker can escape the intended upload directory. This can be leveraged to overwrite sensitive files such as JARs in the classpath, SSH keys, or scheduled tasks, potentially leading to remote code execution (RCE). A patch has been identified in commit 8009845b577d8a2c4bbf4fdd8e8913799a714be6.

Affected products

  • hs-web hsweb-framework <= 5.0.1

Timeline

  • 2026-01-26: disclosed: Issue reported on GitHub and patch committed
  • 2026-06-08: advisory: Published to GitHub Advisory Database and NVD

References

Related threats