Summary
CVE-2026-82460 is a critical path traversal vulnerability in Cloud Commander, a web-based file manager, affecting all versions before 19.20.2. The flaw resides in the REST file-operation and markdown endpoints, which fail to properly validate path normalization, allowing attackers to read, write, move, or copy files outside the application’s configured root directory. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 score of 9.3.
Technical details
- Root cause: The application’s REST file-operation and markdown endpoints do not properly sanitize or resolve path traversal sequences (e.g.,
../) supplied in file path parameters before performing filesystem operations. - Trigger conditions: An attacker sends a crafted request to a REST file-operation endpoint (move, copy, pack, extract) or markdown endpoint, embedding directory traversal sequences (including URL-encoded variants such as
..%2f..%2f..%2f) in the source or destination path parameter. - Attack vector: Network — the CVSS vector (
AV:N/AC:L/PR:N/UI:N) indicates the vulnerability is remotely exploitable over the network with low attack complexity and no user interaction required. - Impact: Successful exploitation allows an attacker to escape the configured root/sandbox directory to read, write, move, or copy arbitrary files on the underlying filesystem, which can lead to disclosure of sensitive files or, in write/move scenarios, tampering with application or system files.
Affected software
- Cloud Commander (npm package
cloudcmd), all versions prior to 19.20.2
Severity
- CVSS v3.1: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Mitigation and recommended actions
- Immediate: Upgrade Cloud Commander to version 19.20.2 or later, which introduces strict path-boundary validation for move, copy, pack, extract, and markdown routing operations.
- If immediate patching is not possible: Restrict network exposure of Cloud Commander instances (place behind authentication and network access controls, avoid exposing directly to the internet), and monitor/restrict inbound requests to REST file-operation and markdown endpoints for path traversal patterns (e.g.,
../, URL-encoded traversal sequences) as an interim compensating control.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Script source URL:
/dist/cloudcmd.common.js

