datacycle-engine dataCycle-CORE
- <= 25.07.3
A path traversal vulnerability has been identified in dataCycle-CORE versions prior to 25.07.3. The issue arises in the module responsible for core processing and framework rules, where the documentation and static markdown renderer improperly handle attacker-controlled path segments. These segments are only sanitized using the Rails HTML sanitizer, which fails to remove directory traversal sequences. As a result, an unauthenticated attacker can escape the designated 'docs' or 'static' directories and access arbitrary '.md' files from either the application root or engine root.
Exploitation of this vulnerability allows for unauthorized access to sensitive documentation files, potentially leading to the disclosure of confidential information.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.