Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-100727: unauthenticated file read in GROWI's local upload mode

CVE-2026-100727: unauthenticated file read in GROWI's local upload mode GROWI, the wiki and collaboration platform published by GROWI, Inc., received a security fix in version 7.5.5 on October 5, 2026. The release closes CVE-2026-100727, an access-control defect that lets an unauthenticated visitor read files kept by pages the platform does not expose publicly. The defect applies to deployments…

On October 5, 2026, GROWI, Inc. released version 7.5.5 to address CVE-2026-100727, an unauthenticated file read vulnerability in GROWI's local upload mode. This security flaw allows an unauthorized visitor to access files stored by the platform on the local file system, impacting deployments that store uploads locally. The vulnerability, rated with a base score of 6.9 (CVSS 4.0) and 5.3 (CVSS 3.0), is classified under CWE-552 as files or directories accessible to external parties.

The exploit is possible when GROWI runs a version lower than 7.5.5 and the file upload setting is configured as "Local." The attack involves an unauthenticated attacker requesting files from non-public pages, which the application serves back upon receiving the request. The impact is limited to confidentiality, as the attacker cannot write or execute files or maintain an authenticated session.

To remediate the issue, GROWI users must update to version 7.5.5 and verify that attachment settings are correctly configured after the upgrade. For those unable to upgrade immediately, moving uploads to an external storage backend can mitigate the vulnerability. Following the patch, it is essential to review non-public pages with attached files from the exposure window and rotate any related credentials or tokens.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

India is Treating Starlink Like Pakistan

Elon Musk has ‘begged’ Indian billionaire Mukesh Ambani to allow Starlink to launch in India’s internet market. In a post … Read More The post India is Treating Starlink Like Pakistan appeared first…

🌿WindQuest-Explore more. Scroll less.

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass What I Built WildQuest — Explore more. Scroll less.

  • WildQuest is an open-source AI app transforming walks into personalized nature quests.
  • Users customize quests by selecting activity, duration, difficulty, and accessibility.
  • App runs locally with Gemma to ensure privacy and independence from cloud AI APIs.

More from Friday 9 October →