MEDIUM 5.5 GitHub

CVE-2025-58363

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

### Summary A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. ### Details In `internal/plugin/native/manager.go`, the plugin installation endpoint (`POST /plugins/*`) constructs a temporary directory path by directly joining user-supplied resource names (`name`) without sufficient sanitization. Supplying path traversal sequences (such as

Affected Products

References

Published: 2026-09-09 · Source: GitHub · Feed updated: 2026-09-11
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-09 via GitHub. Affected: go/github.com/lf-edge/ekuiper/v2 < 2.4.1.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.