{"id":"CVE-2026-96440","published":"2026-09-29T09:17:11.317","lastModified":"2026-09-29T21:33:56.530","description":"Improper Limitation of a Pathname to a Restricted\nDirectory（Path Traversal） in the /WebAgenda/download/uploadFile.jsp\nAPI endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote\nauthenticated users to write files to arbitrary locations outside the intended\nupload directory via the path parameter.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://zuso.ai/cve-advisory/advisory","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}