CVE-2026-11470: Hsweb Fileupload Path Traversal

Potential path traversal due to unsanitized DTO field assignment.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Javaβ
greprules fetch cve-2026-11470-hsweb-fileupload-path-traversal --engine opengrep

Description

Potential path traversal due to unsanitized DTO field assignment.