CRITICAL 9.8 CVE-2026-71805 Published 9 Sept 2026

LZ-litchi Arbitrary File Upload Bug

Worried this affects one of your servers?

LZ-litchi 1.0.0 contains an arbitrary file upload and path traversal vulnerability.

Unauthenticated remote attackers can exploit this flaw by uploading arbitrary files and writing them outside the intended storage directory via the directory parameter in the POST /app-api/infra/file/upload endpoint.

Reference: CVE-2026-71805 on NVD

← Back to Security News