/Vulnerability Library

Nezha Dashboard < 2.0.13 - Path Traversal

CVE-2026-53519
Verified

Description

Nezha Monitoring < 2.0.13 contains a path traversal caused by improper prefix checking in the dashboard's NoRoute handler, letting unauthenticated attackers read arbitrary files via crafted URLs.

Severity

Critical

CVSS Score

9.1

Exploit Probability

2%

Published Date

August 6, 2026

Template Author

aryu-ru, str4k3r

CVE-2026-53519.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-53519
CWE ID:
cwe-22

References

https://github.com/nezhahq/nezha/security/advisories/GHSA-5c25-7vpj-9mqhhttps://nvd.nist.gov/vuln/detail/CVE-2026-53519

Remediation Steps

Update to version 2.0.13 or later.