Executive brief
LZ-litchi is a rapid development platform that provides file upload functionality for applications. The upload endpoint allows unauthenticated remote attackers to upload arbitrary files and use path traversal to write them outside the intended storage directory, potentially enabling code execution, data corruption, or system compromise depending on where files are written and what file types are allowed.
Technical details
The vulnerability exists in the `POST /app-api/infra/file/upload` endpoint in AppFileController.java, which is annotated with `@PermitAll` and accepts user-controlled `directory` and filename parameters without validation or path normalization. The vulnerable code concatenates the user-supplied directory directly into the file path within FileServiceImpl.java's `generateUploadPath()` method without filtering `../` sequences or absolute paths. LocalFileClient.java then concatenates this unsanitized path with the base storage directory without canonical path verification, allowing attackers to escape the intended upload directory. Combined with a secondary vulnerability in the admin-side download endpoint that also lacks path traversal protection, an unauthenticated attacker can upload arbitrary file types and read them back. No authentication is required; the demo environment at litchi.work is confirmed vulnerable.
Affected products
- LZ LZ-litchi <= 1.0.0
Timeline
- 2026-09-09: disclosed
- other: CVE-2026-71805 assigned