- Advisory: GHSA-2w23-rj57-xq9c · CVE-2026-42187
- Severity: Medium · CWE-22
- Status: publicly disclosed and fixed. Reported by Pig-Tail through coordinated disclosure.
Proxy plugin can allow arbitrary file write if local_store is enabled
Write-up only. No standalone runnable PoC is published for this finding here — refer to the linked advisory for full technical detail, affected range, and the fixed version.