Executive brief
LubeLogger is a self-hosted vehicle maintenance tracker. Authenticated users could upload files with specially crafted names to place or overwrite files anywhere on the system with the application's privileges, potentially exposing sensitive data or enabling remote code execution if combined with other attacks.
Technical details
A path traversal vulnerability in HandleTranslationFileUpload allowed authenticated non-administrative users to upload files with crafted names that could escape the intended storage directory. The vulnerable code in FileHelper.cs used simple string replacement to construct the new file path without validating that the resolved path remained under the web root or data directory. An attacker could use directory traversal sequences (e.g., "../") in the upload filename to write files outside intended boundaries, leading to unauthorized file placement or overwrite.
Affected products
- Hargata LubeLogger before 1.6.8
Timeline
- 2026-09-18: disclosed
- 2026-06-25: patched