CVE-2026-48126 | xyproto algernon up to 1.17.7 engine/flags.go path traversal (GHSA-jc3j-x6pg-4hmv)
A vulnerability has been found in xyproto algernon up to 1.17.7 and classified as critical. Impacted is an unknown function of the file engine/flags.go. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-48126. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.