dataCycle-CORE Path Traversal Vulnerability Allowing Arbitrary Markdown File Rendering

Vulnerability

A path traversal vulnerability has been identified in dataCycle-CORE versions prior to 25.07.3. The issue arises in the module responsible for core processing and framework rules, where the documentation and static markdown renderer improperly handle attacker-controlled path segments. These segments are only sanitized using the Rails HTML sanitizer, which fails to remove directory traversal sequences. As a result, an unauthenticated attacker can escape the designated 'docs' or 'static' directories and access arbitrary '.md' files from either the application root or engine root.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive documentation files, potentially leading to the disclosure of confidential information.

Remediation

Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.

Added: Jul 21, 2026, 12:49 AM
Updated: Jul 21, 2026, 12:49 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
9.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.