Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 13 May 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Uncontrolled File Upload in dash-uploader |
Tue, 12 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fohrloop
Fohrloop dash-uploader |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:fohrloop:dash-uploader:*:*:*:*:*:python:*:* cpe:2.3:a:fohrloop:dash-uploader:0.7.0:alpha1:*:*:*:python:*:* cpe:2.3:a:fohrloop:dash-uploader:0.7.0:alpha2:*:*:*:python:*:* |
|
| Vendors & Products |
Fohrloop
Fohrloop dash-uploader |
Fri, 08 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Execution via File Upload in fohrloop Dash-Uploader | |
| Weaknesses | CWE-78 CWE-94 |
Fri, 08 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 CWE-670 |
|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Execution via File Upload in fohrloop Dash-Uploader | |
| Weaknesses | CWE-78 CWE-94 |
Fri, 08 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-08T18:27:31.102Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38361
Updated: 2026-05-08T18:26:05.370Z
Status : Analyzed
Published: 2026-05-08T15:16:37.120
Modified: 2026-05-12T20:55:00.800
Link: CVE-2026-38361
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:51:44Z