Executive brief
DSpace is an open-source platform used by organizations to manage and preserve digital research and scholarly content. A security flaw in its notification service allows an administrator to access unauthorized files on the server. In a worst-case scenario, this could be used to steal sensitive data or take full control of the server by executing malicious code.
Technical details
A path traversal vulnerability exists in the COAR Notify / LDN service of DSpace due to insufficient validation of 'inbound pattern' or 'template' names. The LDN class fails to restrict template file paths to the expected base directory ($dspace.dir/config/ldn), allowing an attacker with DSpace administrator credentials to reference arbitrary files on the filesystem. If an attacker can place a malicious Apache Velocity payload in a predictable location (such as a log file), they can use this vulnerability to include that file as a template, leading to information disclosure or remote code execution. The vulnerability is patched in versions 8.4, 9.3, and 10.0.
Affected products
- DSpace DSpace >= 8.0-rc1, <= 8.3, >= 9.0-rc1, <= 9.2, 10.0-rc1
Timeline
- 2026-06-01: disclosed
- 2026-07-08: advisory
References
- https://api.github.com/users/superpegaso2703
- https://github.com/superpegaso2703
- https://api.github.com/users/superpegaso2703/gists%7B/gist_id%7D
- https://api.github.com/users/superpegaso2703/repos
- https://avatars.githubusercontent.com/u/177873564?v=4
- https://api.github.com/users/superpegaso2703/events%7B/privacy%7D