jfrog-artifactory-oss is vulnerable to Path Traversal
68
Medium Risk
JFrog Artifactory does not sufficiently normalize the path components used when writing artifacts cached through a Docker remote repository. Under specific remote-repository conditions, an authenticated user can steer a cache write outside the intended Docker cache directory to another location the Artifactory process can reach, giving a low-privileged user an arbitrary file write on the host that serves artifacts to downstream builds. The CVSS score of 5.3 reflects an integrity-only impact, but CISA added the issue to its Known Exploited Vulnerabilities catalog on 27 August 2026, so treat it as actively exploited. JFrog has released patched builds on the 7.146 and 7.161 branches; Cloud instances were patched by JFrog.
You are affected if you are using a version that falls within the vulnerable range, you run a self-hosted JFrog Artifactory instance, and you serve Docker remote repositories. Exploitation requires an authenticated user who can pull through the affected remote repository. Cloud-hosted Artifactory instances have already been patched by JFrog and are not vulnerable.
jfrog-artifactory-oss is vulnerable to Path Traversal in versions 0.0.1 - 7.146.34 and 7.161.0 - 7.161.15.
Upgrade the jfrog-artifactory-pro and/or the jfrog-artifactory-oss library to the patch version applicable to your release branch (7.146.35 or 7.161.16).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.