CVE-2026-100520 is a CWE-22 path traversal flaw affecting Laranode versions before 1.2.1. An authenticated user can place directory-traversal sequences in the upload path parameter, bypassing the intended home-directory restriction and writing attacker-controlled files to arbitrary locations accessible to the application. This can include placement of PHP content in another tenant's web root, enabling execution in that tenant's context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains four files: poc.py implements the standalone exploit, requirements.txt declares requests>=2.25, README.md documents the claimed vulnerability and remediation, and .gitignore excludes Python cache artifacts. Python is the implementation language; PHP appears as the embedded payload and in README excerpts of the vulnerable application. The exploit maintains an HTTP session, extracts a Laravel CSRF token from a hidden input or meta tag, submits tenant credentials, and obtains another token. It then sends a single-chunk multipart upload to /filemanager/upload-file with path=../{victim}/{webroot} and a randomly named PHP file. According to the README's vulnerable-code excerpt, unsanitized path concatenation and File::append enable writes outside the tenant home directory; existing-file behavior is append rather than a demonstrated overwrite. The supplied payload runs only fixed identity and system-information commands, although successful PHP placement demonstrates broader code-execution potential. The script is an active exploitation attempt, not merely a detector. Its destination-string check is only an indicator of traversal and does not independently establish that the file exists or executes. Unlike the README's example output, the implementation does not automatically verify RCE. Its printed verification URL may also incorrectly include public_html. No cleanup is implemented, so successful uploads leave the marker behind. There are no hardcoded callback or exfiltration destinations. The CVE identifier, affected range, and fix claims are supplied by the repository and have not been independently verified. The original repository URL, analyzed git reference, and archive size were not provided; empty strings and zero represent unavailable metadata.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated path-traversal flaw in Laranode versions before 1.2.1 in the POST /filemanager/upload-file endpoint. It permits writing arbitrary files outside the authenticated user's home directory, potentially enabling cross-tenant PHP file placement and code execution as another tenant.
An authenticated path-traversal flaw in Laranode prior to version 1.2.1's file-manager upload endpoint. It permits arbitrary file writes outside the authenticated user's home directory and can enable cross-tenant PHP code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.