CVE-2026-7271 Details
Description
A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The patch is named 3d255865a957f3740b8724dd914502c0f44d4970. Applying a patch is the recommended action to fix this issue.
A path traversal vulnerability has been identified in DV0x Creative Ad Agent versions prior to commit 751b9e5146604dc65049bd0f62dcbdad6212f8a3. The issue resides in the Creative Ad Agent Server component, specifically within the file server/sdk-server.ts. The vulnerability arises because the endpoint /images/:sessionId?/:filename accepts user-controlled parameters and constructs a filesystem path without proper validation. This lack of validation allows an attacker to manipulate the path and access arbitrary files on the server, including sensitive host files like /etc/hosts. The vulnerability can be exploited remotely, and an exploit is publicly available.
Users are advised to update to the patched version, which is available in the same repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DV0x/creative-ad-agent/ | [email protected] | ProductVendor |
| https://github.com/DV0x/creative-ad-agent/commit/3d255865a957f3740b8724dd914502c0f44d4970 | [email protected] | Source CodeVendor |
| https://github.com/DV0x/creative-ad-agent/issues/1 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/802887 | [email protected] | Technical Description |
| https://vuldb.com/vuln/359926 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/vuln/359926/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DV0x creative-ad-agent | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion