Relative Path Traversal in Opencast - CVE-2025-55202
Published: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the UI config module when handling file path requests. A remote attacker can request a crafted path to disclose sensitive information.
Exploitation is limited to files in another folder whose path starts with the configured ui-config path and that are readable by Opencast.