MEDIUM 5.5 GitHub
CVE-2025-58363
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
### Summary
A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system.
### Details
In `internal/plugin/native/manager.go`, the plugin installation endpoint (`POST /plugins/*`) constructs a temporary directory path by directly joining user-supplied resource names (`name`) without sufficient sanitization. Supplying path traversal sequences (such as
Affected Products
- go/github.com/lf-edge/ekuiper/v2 < 2.4.1
References
- https://github.com/advisories/GHSA-c23q-fw86-9h5x
- https://github.com/lf-edge/ekuiper/security/advisories/GHSA-c23q-fw86-9h5x
- https://github.com/lf-edge/ekuiper/releases/tag/v2.4.1
- https://github.com/advisories/GHSA-c23q-fw86-9h5x
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-09 via GitHub. Affected: go/github.com/lf-edge/ekuiper/v2 < 2.4.1.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.