Junglewise Threat Intelligence

CVE-2026-49830: DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.

CVE-2026-49830 · Severity: medium · CVSS 4.4 · Published 2026-09-02

Technologies: Dspace.

Executive brief

DSpace is an open-source platform used by organizations to manage and preserve digital research and scholarly content. A security flaw in its data harvesting component allows an authorized administrator to trick the system into importing sensitive internal files from the server's hard drive. This could lead to the exposure of private system information or configuration files to unauthorized parties.

Technical details

A local file inclusion (LFI) vulnerability exists in the DSpace ORE Ingestion Crosswalk component. The root cause is a failure to validate URI schemes when ingesting aggregated ORE resources via the OAI-ORE Harvester. An attacker with Collection, Community, or Site Administrator privileges can configure a harvest source to point to local system paths (e.g., using the 'file://' scheme), causing the server to ingest sensitive local files as bitstreams. This can also be exploited if a trusted OAI endpoint is compromised and serves malicious XML. Patches are available in versions 7.6.7, 8.4, 9.3, and 10.0.

Affected products

  • DSpace DSpace <= 7.6.6, 8.0 <= 8.3, 9.0 <= 9.2, 10-rc1

Timeline

  • 2026-06-01: disclosed: Initial disclosure to DSpace/DSpace repository
  • 2026-07-08: advisory: GitHub Advisory published

References