CVE-2026-6815 is an arbitrary file write vulnerability in Casdoor's Local File System storage provider. The issue is caused by insufficient path sanitization when handling file paths for uploaded or stored content. An authenticated attacker with elevated privileges (described in the provided content as administrative privileges, and in one mention as file upload privileges) can supply path traversal sequences to escape the application's intended storage directory and create or overwrite files at attacker-controlled locations on the underlying host filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a small standalone Python PoC for CVE-2026-6815 affecting Casdoor versions earlier than 3.54.1. It contains one exploit script (CVE-2026-6815.py), a README with usage and impact notes, and a requirements file listing the requests dependency. The exploit is not part of a larger framework. The Python script uses requests.Session to interact with a target Casdoor instance over HTTP(S). Based on the visible code and README, its workflow is: initialize a session and authenticate with supplied credentials, create or reuse a Local File System storage provider configured with a traversal-based pathPrefix, then call the Casdoor upload API to send an attacker-controlled local file to an arbitrary absolute path on the server using parameters such as owner, user, application, fullFilePath, and provider=path_traversal. Verbose mode logs raw HTTP request/response details. Primary capability is authenticated arbitrary file write outside the intended storage sandbox. The repository explicitly describes post-exploitation uses including SSH authorized_keys injection, web shell upload into another webroot, and destructive overwrite of application data such as casdoor.db for denial of service. Because the payload is simply any local file chosen by the operator and the destination path is operator-controlled, the exploit is operational rather than a mere detection script. Fingerprintable targets/endpoints include the Casdoor API path /api/upload-resource and example filesystem targets /home/casdoor/.ssh/authorized_keys, /app/casdoor.db, /var/www/html/shell.php, and /tmp/pwned.txt. The exploit requires valid admin or equivalent credentials and success depends on the filesystem permissions of the Casdoor service account.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.