OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request path, an attacker can traverse outside the intended directory and read any file OpenDeck can access. This vulnerability is fixed in 2.8.1.
History

Wed, 04 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
Description OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request path, an attacker can traverse outside the intended directory and read any file OpenDeck can access. This vulnerability is fixed in 2.8.1.
Title OpenDeck affected by path traversal allows arbitrary file read
Weaknesses CWE-22
CWE-24
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-03-04T19:30:07.137Z

Updated: 2026-03-04T21:05:38.200Z

Reserved: 2026-02-27T15:54:05.137Z

Link: CVE-2026-28427

cve-icon Vulnrichment

Updated: 2026-03-04T21:05:25.327Z

cve-icon NVD

Status : Received

Published: 2026-03-04T20:16:19.640

Modified: 2026-03-04T20:16:19.640

Link: CVE-2026-28427

cve-icon Redhat

No data.