Executive brief
The AIL Framework, a platform used for analyzing information leaks, contains a security flaw in its investigation workflow. An authorized user can manipulate file requests to access sensitive data stored on the server that they should not be able to see. This could lead to the exposure of internal system files or other confidential information managed by the application.
Technical details
A path traversal vulnerability (CWE-22) exists in the AIL Framework's investigation download functionality. The root cause is the improper sanitization of user-controlled object identifiers, which are joined with application storage paths without verifying that the resulting path remains within the intended directories (such as images, favicons, or screenshots). An authenticated attacker can exploit this by supplying crafted identifiers to resolve paths outside these restricted directories. This allows the attacker to include arbitrary files accessible to the AIL process in a generated download archive. The issue is fixed in the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f.
Affected products
- AIL Project AIL Framework versions up to and including 6.8.0
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory