216.73.216.6

CVE-2026-42598

· Published 14/05/2026 18:16 · Modified 14/05/2026 18:27

Labels: CVE-2026-42598 2026-05-14CVE-2026-42598CWE-22[email protected]

Essential information

Published
14/05/2026 18:16
Modified
14/05/2026 18:27
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the contents returned. This vulnerability is fixed in 2.13.0.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pode / pode cpe:2.3:a:pode:pode:2.4.0:*:*:*:*:*:*:*
pode / pode cpe:2.3:a:pode:pode:<2.13.0:*:*:*:*:*:*:*

References