Description
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestService.java of the component SVG File Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 1.4.5.1 is able to resolve this issue. This patch is called 975e39e4dd527596987559f56c5f9f973f64eff7. It is recommended to upgrade the affected component.
INFO
Published Date :
2026-03-08T16:02:14.273Z
Last Modified :
2026-03-11T19:39:49.199Z
Source :
VulDB
AFFECTED PRODUCTS
The following products are affected by CVE-2026-3749 vulnerability.
| Vendors | Products |
|---|---|
| Bytedesk |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-3749.