CVE-2026-103398
Last modified
CVE-2026-103398 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes..
Description
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Liquid-co | OpenSave | <= 2.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103398?
How severe is CVE-2026-103398?
How do I fix CVE-2026-103398?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103387A weakness has been identified in garycourt uri-js up to 4.4…4.3
- CVE-2026-103388MISP renders the source field of a Galaxy Cluster as a click…6.2
- CVE-2026-103389MISP contains a stored cross-site scripting (XSS) vulnerabil…6.2
- CVE-2026-103395LightLLM through 1.2.0 visual_only deployments expose an una…9.8
- CVE-2026-103396bbs-go through 4.4.6 contains a permission bypass vulnerabil…4.3
- CVE-2026-103397OpenSave before 2.4.0-beta.1 fails to validate sender identi…5.6
- CVE-2026-103399A flaw was found in SoupServer (libsoup). When an HTTP/1.x c…5.3
- CVE-2026-103431colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT…7.7
- CVE-2026-103432apcupsd through 3.14.14 has an sscanf stack-based buffer ove…8.1
- CVE-2026-103436apcupsd through 3.14.14 discloses uninitialized stack memory…3.7
- CVE-2026-103437Improper neutralization of Script-Related HTML tags in a web…1.1
- CVE-2026-103438Improper neutralization of Script-Related HTML tags in a web…0.3
Are you affected by CVE-2026-103398?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
