Junglewise Threat Intelligence

CVE-2026-41951: GROWI path traversal in EJS template execution

CVE-2026-41951 · Severity: high · CVSS 7.2 · Published 2026-05-11

Technologies: GROWI. Vendors: WESEEK.

Executive brief

GROWI is a popular open-source wiki and knowledge management platform. A security flaw in its file handling allows an attacker with high-level administrative privileges to access restricted directories on the server. If an email server is configured within the application, this could lead to the execution of malicious code, potentially resulting in a full system takeover or data theft.

Technical details

A path traversal vulnerability (CWE-22) exists in GROWI versions v7.5.0 and earlier. The flaw is exploitable when an email server is configured within the GROWI environment. An attacker with high privileges (PR:H) can leverage this vulnerability to bypass directory restrictions and execute arbitrary EJS (Embedded JavaScript) templates on the host server. This can lead to remote code execution (RCE), arbitrary OS command execution, or a denial-of-service (DoS) condition. The issue is resolved in GROWI v7.5.1.

Affected products

  • GROWI GROWI v7.5.0 and earlier

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory
  • 2026-05-11: patched: Fixed in version v7.5.1

References