Junglewise Threat Intelligence

CVE-2026-53528: LeafWiki path traversal in asset rename

CVE-2026-53528 · Severity: high · CVSS 8.8 · Published 2026-08-21

Technologies: LeafWiki. Vendors: LeafWiki.

Executive brief

LeafWiki is a self-hosted wiki platform that allows organizations to create and manage internal documentation. A vulnerability in its asset rename feature allows authenticated editors to move any file accessible to the LeafWiki server—including sensitive databases or configuration files—into publicly downloadable locations. This could expose confidential data or disrupt the wiki's operation entirely.

Technical details

A path traversal vulnerability exists in LeafWiki's PUT /api/pages/<pageID>/assets/rename endpoint due to insufficient sanitization of the oldFilename parameter. An attacker can inject path traversal sequences such as ../ to reference and move files outside the intended asset directory. The vulnerability requires an authenticated session with editor permissions and a valid page ID, but no additional user interaction. A successful exploit allows file exfiltration, integrity compromise of critical application files (including the database), and denial of service through file manipulation. The vulnerability is fixed in version 0.10.1 and later.

Affected products

  • LeafWiki LeafWiki 0.3.0 through 0.10.0

Timeline

  • 2026-05-31: disclosed
  • 2026-08-21: advisory
  • 2026: patched: version 0.10.1 and later

References

Related threats