Executive brief
DataEase, an open-source data visualization and analysis tool, contains a security flaw in its export management system. An authenticated user can exploit this vulnerability to delete important files and folders across the entire server where the software is installed. This could lead to a complete service outage or the loss of critical system data.
Technical details
A path traversal vulnerability exists in the DataEase export-center bulk delete API endpoint. The application fails to properly sanitize user-provided identifiers before passing them to the ExportCenterManage.delete method. An authenticated attacker can inject path traversal sequences (e.g., '../../') to escape the intended directory and trigger a recursive deletion of arbitrary directories on the host server. This occurs during the export task cleanup process. The vulnerability is addressed in version 2.10.23 by implementing stricter validation on the identifiers used for file operations.
Affected products
- DataEase DataEase < 2.10.23
Timeline
- 2026-05-28: patched: Fixed in version 2.10.23
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: CVE published to NVD