CYBERHAWK / CVE / CVE-2026-49136

CVE-2026-49136

Banana Slides

HIGH CVSS 7.5 ai

The flaw

Path traversal vulnerability in generate_image() function allows reading arbitrary image files outside uploads directory.

What to do

Update to Banana Slides version later than 0.4.0

▸ Scan my repo for CVE-2026-49136

References

First seen 2026-06-05 · Tracked by PickBits CyberHawk · Weekly CVE digest