CVE-2026-5013 | elecV2 elecV2P up to 3.8.3 /store/:key path.join URL path traversal (Issue 199 / EUVD-2026-16945)
A vulnerability was found in elecV2 elecV2P up to 3.8.3. It has been classified as critical. Impacted is the function path.join of the file /store/:key. The manipulation of the argument URL leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-5013. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.