Executive brief
The AIL Framework, a platform for analyzing information leaks, contains a security flaw in how it handles PDF files. An authorized user could exploit this to access sensitive files on the server that they should not be able to see, such as system configurations or credentials. This could lead to the exposure of private data or further compromise of the hosting environment.
Technical details
A path traversal vulnerability (CWE-22) exists in the PDF.get_filepath() function of the AIL Framework. The function fails to validate that a file path constructed from a PDF object identifier remains within the designated PDF_FOLDER directory. An authenticated attacker can provide crafted identifiers containing relative traversal sequences (e.g., ../) or absolute paths to access files outside the intended directory. The vulnerability is mitigated in commit 14c618fce4d1df02358717c48ea903706abecdf2 by using os.path.realpath() and verifying the common path against the configured PDF directory.
Affected products
- ail-project AIL Framework versions up to and including v6.9.0
Timeline
- 2026-07-05: disclosed
- 2026-07-05: patched: Fixed in commit 14c618fce4d1df02358717c48ea903706abecdf2
- 2026-07-05: advisory