CRITICAL
9.8 CVE-2026-71805 Published 9 Sept 2026
LZ-litchi Arbitrary File Upload Bug
Worried this affects one of your servers?
LZ-litchi 1.0.0 contains an arbitrary file upload and path traversal vulnerability.
Unauthenticated remote attackers can exploit this flaw by uploading arbitrary files and writing them outside the intended storage directory via the directory parameter in the POST /app-api/infra/file/upload endpoint.
Reference: CVE-2026-71805 on NVD
← Back to Security News