A vulnerability classified as problematic has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name leads to path traversal. This vulnerability is referenced as CVE-2026-105174. Remote... Weiterlesen: CVE-2026-105174 | Gerapy up to 0.9.13 Project Management views.py pro…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-105174 | Gerapy up to 0.9.13 Project Management views.py project_create project_name path traversal (Issue 317 / EUVD-2026-92154)
A vulnerability classified as problematic has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2026-105174
NVD: DeferredNVD 5.4 · MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
NVD-Datenstand: 06.10.2026, 23:16 UTC
Ausnutzung beobachtet: Public PoC Automatisierbar: Nein Technischer Impact: Teilweise
CISA-SSVC-Triage (vulnrichment)CVE-2026-105174
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-06T22:18:10.169308Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
Intelligence Digest — kostenlos Täglich die wichtigsten Security-News · jederzeit abbestellbar