Path traversal in OneDev - #VU129816
Published: May 5, 2026
OneDev
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in Git LFS pointer resolution when processing repository-controlled LFS metadata. A remote user can push a crafted repository object to disclose sensitive information.
Exploitation requires push permission to a repository.