Intel

AIKIDO-2026-209605

jfrog-artifactory-oss is vulnerable to Path Traversal

Path TraversalCVE-2026-66384 Published Yesterday

68

Medium Risk

This Affects:

OSjfrog-artifactory-oss
0.0.1 - 7.146.34
Fixed in 7.146.35
7.161.0 - 7.161.15
Fixed in 7.161.16
Are you affected? Scan for Free

TL;DR

JFrog Artifactory does not sufficiently normalize the path components used when writing artifacts cached through a Docker remote repository. Under specific remote-repository conditions, an authenticated user can steer a cache write outside the intended Docker cache directory to another location the Artifactory process can reach, giving a low-privileged user an arbitrary file write on the host that serves artifacts to downstream builds. The CVSS score of 5.3 reflects an integrity-only impact, but CISA added the issue to its Known Exploited Vulnerabilities catalog on 27 August 2026, so treat it as actively exploited. JFrog has released patched builds on the 7.146 and 7.161 branches; Cloud instances were patched by JFrog.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range, you run a self-hosted JFrog Artifactory instance, and you serve Docker remote repositories. Exploitation requires an authenticated user who can pull through the affected remote repository. Cloud-hosted Artifactory instances have already been patched by JFrog and are not vulnerable.

Background info

jfrog-artifactory-oss is vulnerable to Path Traversal in versions 0.0.1 - 7.146.34 and 7.161.0 - 7.161.15.

How to fix this

Upgrade the jfrog-artifactory-pro and/or the jfrog-artifactory-oss library to the patch version applicable to your release branch (7.146.35 or 7.161.16).

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform