CVE-2026-49830
4.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Summary
DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via malicious paths like file:///etc/passwd. The attacker MUST already have DSpace collection administrator privileges in order to perform the attack. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DSpace | DSpace | < 7.6.7 | affected |
| DSpace | DSpace | >= 8.0-rc1, < 8.4 | affected |
| DSpace | DSpace | >= 9.0-rc1, < 9.3 | affected |
| DSpace | DSpace | = 10-rc1 | affected |
Weaknesses
- CWE-20: CWE-20: Improper Input Validation
References
- https://github.com/DSpace/DSpace/security/advisories/GHSA-c827-pw3m-67w7
- https://github.com/DSpace/DSpace/pull/12541
- https://github.com/DSpace/DSpace/pull/12542
- https://github.com/DSpace/DSpace/pull/12543
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.