CVE-2026-41231 | Froxlor up to 2.3.5 Destination DataDump.add fixed_homedir link following (GHSA-75h4-c557-j89r / EUVD-2026-25182)
A vulnerability marked as critical has been reported in Froxlor up to 2.3.5. This affects the function DataDump.add of the component Destination Handler. Performing a manipulation of the argument fixed_homedir results in link following.
This vulnerability is reported as CVE-2026-41231. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.