CNNVD-202602-2219 Information
CNNVD ID
CNNVD-202602-2219
Related CVE
- CNNVD Published: 2026-02-13
Description (Chinese)
Tandoor Recipes是Tandoor Recipes开源的一个用于管理食谱、计划膳食、建立购物清单等等的应用程序。 Tandoor Recipes 2.5.1之前版本存在安全漏洞,该漏洞源于RecipeImport工作流中缺少对file_path参数的输入验证,可能导致经过身份验证的用户读取服务器上的任意文件。
Description (English)
Tandoor Recipes is an application for the management of recipes, the planning of meals, the creation of shopping lists, etc. There was a security loophole in the pre-Tandoor Recipes 2.5.1 version, which stemmed from the lack of input authentication of file path parameters in the RecipeImport workflow, which could lead to any document on the server being read by an identified user.
Vulnerability Type
其他
Affected Vendor
Tandoor Recipes
Published
2026-02-13
Last Modified
2026-02-24
References
https://github.com/TandoorRecipes/recipes/commit/f7f3524609451ab0b5a4fd760ad0af147d8ed794 https://github.com/TandoorRecipes/recipes/releases/tag/2.5.1 https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-6485-jr28-52xx
Patch
https://github.com/TandoorRecipes/recipes/releases/
Share on: