Junglewise Threat Intelligence

CVE-2026-45053: CubeCart arbitrary file upload and path traversal in REST API

CVE-2026-45053 · Severity: critical · CVSS 9.1 · Published 2026-05-13

Technologies: CubeCart. Vendors: CubeCart.

Executive brief

CubeCart is an e-commerce platform used by businesses to manage online stores and process customer orders. A security flaw in the software's file management system allows an authorized user or integrated third-party service to upload malicious code to the server. If exploited, an attacker could take full control of the online store, steal sensitive customer data, exfiltrate payment information, or disrupt business operations.

Technical details

An arbitrary file upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart due to insufficient validation in 'classes/api/resources/apiresource_files.class.php'. The application fails to restrict executable file extensions and does not invoke standard security validators, allowing PHP files to be uploaded to the web-accessible 'images/source/' directory. Furthermore, a path traversal flaw in the 'filepath' parameter allows attackers to escape the intended directory and write files to the document root. An attacker with an API key possessing 'files:rw' permissions can exploit these flaws to achieve remote code execution (RCE). The vulnerability is fixed in version 6.7.0.

Affected products

  • CubeCart CubeCart 6.6.x, prior to 6.7.0

Timeline

  • 2026-05-07: advisory: Original GitHub security advisory published
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats