MEDIUM6.1
GHSA-m63q-4hr8-5r5h
Solon Vulnerable to Directory Traversal
Quick fix
GHSA-m63q-4hr8-5r5h — org.noear:solon-faas-luffy: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.2.0</version> for org.noear:solon-faas-luffyDetails
Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.noear:solon-faas-luffy
Introduced in:
3.1.2Fixed in: 3.2.0Fix
# pom.xml: bump <version>3.2.0</version> for org.noear:solon-faas-luffyReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-46096[ADVISORY]
- https://github.com/opensolon/solon/issues/357[WEB]
- https://github.com/opensolon/solon/commit/49a3bf95fdcf050829843004b65a2b336ca6ddff[WEB]
- https://gist.github.com/yaoyao-cool/1b7d80930fea88b6fd4839646cedc437[WEB]
- https://github.com/opensolon/solon[PACKAGE]