process_cert_files of the file backend/service/upload_service.py. The manipulation of the argument task_id leads to path traversal.This vulnerability is known as CVE-2025-8729. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
SOCIAL SHARE CARD GENERATOR