CVE-2026-32707: Px4 Mavlink Ftp Path Traversal

MAVLink FTP component constructs paths from untrusted user input without path-traversal validation, allowing file operations outside the intended root directory.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C++
greprules fetch cve-2026-32707-px4-mavlink-ftp-path-traversal --engine opengrep

Description

MAVLink FTP component constructs paths from untrusted user input without path-traversal validation, allowing file operations outside the intended root directory.