CVE-2026-88394

CVE-2026-88394 published: WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside t...

View full NVD advisory → ← Back to CVE watch