Summary
CVE-2026-71805 is a critical (CVSS 9.8) unauthenticated arbitrary file upload and path traversal vulnerability in LZ-litchi, a Java-based rapid development platform, affecting version 1.0.0 (and earlier). The flaw allows unauthenticated, remote attackers to upload files to arbitrary filesystem locations and subsequently retrieve them, forming a complete anonymous read/write attack chain that can lead to remote code execution or full system compromise.
Technical details
- Root cause: The file upload endpoint is annotated with
@PermitAll, bypassing authentication, and the user-supplieddirectoryparameter is concatenated directly into the server’s base storage path (config.getBasePath() + File.separator + path) without canonicalization or filtering of../sequences. - Trigger conditions: An attacker sends a crafted multipart POST request to
/app-api/infra/file/uploadwith adirectoryvalue containing directory traversal sequences (e.g.,../../../../../../tmp) and an arbitrary file payload; the file type restriction (fileType=allin default/demo configuration) does not block dangerous file extensions. - Attack vector: Network-based, no authentication or user interaction required (AV:N/AC:L/PR:N/UI:N).
- Impact: Attackers can write files outside the intended upload directory (potentially including web-accessible or executable paths) and, via a related unauthenticated download endpoint (
GET /admin-api/infra/file/{configKey}/get/**, also@PermitAlland only URL-decoding paths without filtering../), read arbitrary files from the server. Combined, these primitives can be leveraged to plant and later retrieve/execute malicious files, resulting in high confidentiality, integrity, and availability impact.
Affected software
- LZ-litchi Rapid Development Platform, version 1.0.0 and earlier (≤ 1.0.0)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CWE: CWE-434 (Unrestricted Upload of File with Dangerous Type)
Mitigation and recommended actions
- Immediate: Upgrade LZ-litchi to a version beyond 1.0.0 that removes the
@PermitAllannotation from the file upload (/app-api/infra/file/upload,/app-api/infra/file/create) and file download (/admin-api/infra/file/{configKey}/get/**) endpoints and requires proper authentication. - If no patch is available:
- Restrict or disable public access to the affected upload and download endpoints at the network/reverse-proxy layer until a fix is applied.
- Implement server-side path normalization/canonicalization (e.g.,
getCanonicalPath()) to reject requests where the resolved path escapes the configured base upload directory. - Enforce an allow-list of permitted file extensions/types instead of relying on an "allow all" configuration.
- Generate randomized, server-controlled filenames and storage paths rather than trusting user-supplied
directoryor filename values. - Deploy WAF rules to detect and block path traversal sequences (
../, encoded variants) in upload-related POST parameters as a temporary compensating control.

