← Back

Sharelatex

sharelatex

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Sharelatex
sharelatex

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sharelatex
1Sharelatex
May 6, 2026
Mar 4, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code via ` (backtick) characters in a filename.
1Sharelatex
1Sharelatex
May 6, 2026
Mar 4, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, allows remote authenticated users to read arbitrary files via a \include command.