Junglewise Threat Intelligence

CVE-2026-75333: yx-image-recognition path traversal in file operations

CVE-2026-75333 · Severity: high · CVSS 7.5 · Published 2026-08-26

Executive brief

yx-image-recognition is a Spring Boot-based image recognition system that processes file and directory requests from users. The system fails to validate file paths before accessing the filesystem, allowing an attacker to read any file or list any directory on the server without authentication. An exploit could expose sensitive configuration files, source code, credentials, or other confidential data stored on the server.

Technical details

The vulnerability is a classic path traversal flaw in which user-supplied path parameters (dir, filePath) are passed directly to Java's File() constructor without sanitization or validation. Multiple Spring MVC controller methods in FileController, PlateController, FaceController, and CardController are affected. The application performs only URL decoding on input—no canonical path checks, no ../ filtering, and no whitelist of allowed directories. No authentication is required; the vulnerable endpoints are publicly accessible via HTTP GET requests. An attacker can manipulate path parameters to traverse the filesystem and read arbitrary files or enumerate directory contents.

Affected products

  • yx-image-recognition yx-image-recognition 1.0

Timeline

  • 2026-08-26: disclosed
  • other: CVE-2026-75333 assigned

References