{"id":"CVE-2026-55631","summary":"DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management","details":"DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record is later deleted, the backend concatenates that stored value with the font storage directory and passes it to FileUtils.deleteFile() without path traversal sanitization, allowing deletion of arbitrary writable files in the application container. This issue is fixed in version 2.10.24.","aliases":["GHSA-r99p-w8fc-93g6"],"modified":"2026-08-12T16:41:19.952984Z","published":"2026-07-07T20:24:56.074Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55631.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/dataease/dataease/releases/tag/v2.10.24"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55631.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-r99p-w8fc-93g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55631"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"8892a6945b0b7a329a156155270fae58afa895bc"},{"fixed":"fa0889fcff354966b66d037ad843b7b402dbc4ce"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.10.24"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.10.23","v2.10.22","v2.10.21","v2.10.20","v2.10.19","v2.10.18","v2.10.17","v2.10.16","v2.10.15","v2.10.14","v2.10.13","v2.10.12","v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.6.0","v2.3.0","v2.2.0","v1.0.0"],"database_specific":{"vanir_signatures":[{"id":"CVE-2026-55631-5d5c5930","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc","target":{"function":"delete","file":"core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java"},"deprecated":false,"digest":{"function_hash":"244233215273914117458446441631952138559","length":255}},{"source":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc","target":{"file":"core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java","function":"saveFile"},"deprecated":false,"digest":{"function_hash":"110532318672023542130070984861619925582","length":1259},"id":"CVE-2026-55631-619b4f2b","signature_type":"Function","signature_version":"v1"},{"target":{"file":"core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["63159729901470746290636832661553375134","254977216913930496287965249616743101646","108393760933712085524019361615094154663","93159895124701603671994202556886434113","194643405299870811938125400673145403092","237562987073151532833588986845063241828","284674546177607229397683295881590585316","93312402125165903041919484256090564764","84796939952385348728294174970208176386","325929475112713340823352271172927019347","319438752948240298319782252874182265145","303857041069560874483884832150449532640","64107328558196836039315084867106064531","314266046386674264566683725051921724683","126293794730870951881842463561363556316","319770128164839963889652529837651538178","2187252367853771841366408788439057906","241966785648540725919756540218692638440","322347462758980149897007254705502284460","280415025413215721729155263325254886303","78574262110037086758399944937965597454","2685138546016725535967955298629049312","101767532219190243343308005619767494490","218936612606481723353482909796225676826","81911723586227577603253238037921130645","126340126962237487779690566616125131642","129593585901156141992934611210779813852","265712334956033978505678542816544646019","212525010383229476084849277988061519808","63327458639553807947383498329302576614","156641677648576620471917334304911043731","2344603587248918934372378637422257946","8187814050556705114116370661888263381","301253090954672984394583223585257816528","316891952157542929877604455638789522826","98808140357322518789595172348283739535","19367855476103740280580691361188943643","278105376289709436054898777519586569432","147133147016680477418817864818548911621","283924489427764317724310395169416143193","151753797279278870893917404496585813713","133409091021178258385160949281826715359","22302905449319542772865721804489943159","214230374094766644341249757429374730112","90547565012791624982162580342442302099","298415729604903282662075205240220450402","146279542286153212638730213007289857183","96223915531727605223996191801214234269","139259571595527651539574538238689584349","180131802963564949869479895534928224186","314814686438099284831046069602001713633","54592930225335029664957332385552176127","313066800682951810455367421214274071333","41822724773901750817045339881023665377","270127306289725748055042564561162633058","338573240930918413366190257047149140611","909909405323769675332084097946427570"]},"id":"CVE-2026-55631-715eb1cf","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc","target":{"file":"core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java","function":"download"},"deprecated":false,"digest":{"function_hash":"212511868958027570421057111574534705469","length":807},"id":"CVE-2026-55631-b5269ba7"},{"deprecated":false,"digest":{"function_hash":"316159376187064092988902337895079880942","length":445},"id":"CVE-2026-55631-c6df24a0","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc","target":{"file":"core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java","function":"create"}},{"signature_version":"v1","source":"https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc","target":{"file":"core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java","function":"edit"},"deprecated":false,"digest":{"length":500,"function_hash":"212395036784794400859677715686853402280"},"id":"CVE-2026-55631-e6c13077","signature_type":"Function"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55631.json","vanir_signatures_modified":"2026-08-12T16:41:19Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}