CVE-2021-41324
NixOS vulnerability analysis and mitigation

Overview

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete). The vulnerability was discovered by security researcher Robin Descamps from NTT Belgium and was fixed in version 2.2.12 (Pydio Release).

Technical details

The vulnerability exists in three features: Copy, Move and Delete. For Copy/Move features, the vulnerability is exploitable via the 'nodes' parameter in the web request. For the Delete feature, it's exploitable via the 'Path' parameter. When exploited, the application returns different HTTP error codes that allow determining if files exist: a 403 error if the file exists and a 404/500 error if it doesn't exist. This enables enumeration of valid file names in any user's personal folder or in any 'Cell' (CharonV Advisory).

Impact

The vulnerability allows authenticated attackers to enumerate valid file names in any user's personal folder or in any 'Cell', even those they don't have access to. This could lead to unauthorized information disclosure and potential privacy violations (CharonV Advisory).

Mitigation and workarounds

Users should upgrade to Pydio Cells version 2.2.12 or above, which contains fixes for this vulnerability. The upgrade can be performed using the in-app dashboard in Cells Console > Software Updates, or by replacing the binary and restarting (Pydio Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management