CVE-2026-40163 | Saltcorn up to 1.4.4/1.5.4/1.6.0-beta.3 JSON File Parser /sync/offline_changes path traversal (GHSA-32pv-mpqg-h292)
A vulnerability was found in Saltcorn up to 1.4.4/1.5.4/1.6.0-beta.3. It has been rated as critical. This affects an unknown function of the file /sync/offline_changes of the component JSON File Parser. This manipulation causes path traversal.
This vulnerability is handled as CVE-2026-40163. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.