Junglewise Threat Intelligence

CVE-2026-33166: Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)

CVE-2026-33166 · Severity: low · CVSS 3.1 · Published 2026-03-18

Vendors: Maven.

Executive brief

Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)

Affected products

  • Maven io.qameta.allure:allure-generator

Related threats