CNNVD-202602-2219 Information

CNNVD ID

CNNVD-202602-2219

CVE-2026-25964

  • CNNVD Published: 2026-02-13

Description (Chinese)

Tandoor Recipes是Tandoor Recipes开源的一个用于管理食谱、计划膳食、建立购物清单等等的应用程序。 Tandoor Recipes 2.5.1之前版本存在安全漏洞,该漏洞源于RecipeImport工作流中缺少对file_path参数的输入验证,可能导致经过身份验证的用户读取服务器上的任意文件。

Description (English)

Tandoor Recipes is an application for the management of recipes, the planning of meals, the creation of shopping lists, etc. There was a security loophole in the pre-Tandoor Recipes 2.5.1 version, which stemmed from the lack of input authentication of file path parameters in the RecipeImport workflow, which could lead to any document on the server being read by an identified user.

Vulnerability Type

其他

Affected Vendor

Tandoor Recipes

Published

2026-02-13

Last Modified

2026-02-24

References

https://github.com/TandoorRecipes/recipes/commit/f7f3524609451ab0b5a4fd760ad0af147d8ed794 https://github.com/TandoorRecipes/recipes/releases/tag/2.5.1 https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-6485-jr28-52xx

Patch

https://github.com/TandoorRecipes/recipes/releases/

Share on: