Security Advisory

CVE-2026-61505

5.3
MEDIUM

Vulnerability Description

Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the shared folders. Exploitation is constrained to files matching a narrow naming and format pattern, limiting practical impact.
Published Date July 13, 2026
Official Source NIST NVD Advisory