Veno File Manager Project 4.4.9 contains a path traversal flaw in its translations-update functionality. An attacker can supply a manipulated removal parameter to cause deletion of files outside the intended translations scope.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept exploit for CVE-2026-37065 affecting Veno File Manager 4.4.9. It contains two files: a Bash exploit script (PoC.sh) and a README describing the issue. The exploit is not part of a larger framework. The main capability is authenticated arbitrary file deletion through the VFM administrative translations feature. The script requires four arguments: session cookie name, session cookie value, target file path relative to the application root and without extension, and the base URL of the VFM installation. It performs two POST requests with curl: first to /vfm-admin/index.php?section=translations&action=update with thenewlang=ca to force creation/use of the translations directory, then to the same endpoint with remove=../../../<target path> to exploit path traversal and delete the chosen file. The script comments and output indicate the intended target is a PHP file, and it prints the deleted path as <base>/<target>.php. Operationally, this is an authenticated web exploit requiring superadmin privileges and a valid session cookie. It does not provide code execution or a shell; its impact is destructive file deletion, which can cause denial of service or application breakage if critical files such as index.php are removed. The repository is concise and purpose-built, with no auxiliary tooling, persistence, or detection logic.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.