Path Traversal: \'../filedir\' in XWiki platform - CVE-2026-48047
Published: May 21, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to write arbitrary files.
The vulnerability exists due to path traversal in the WebJar extension handling in xwiki-platform-webjars-api when installing a malicious WebJar extension. A remote privileged user can install a specially crafted extension to write arbitrary files.
Exploitation requires that a malicious extension be available in an extension repository configured in the instance.