A vulnerability classified as problematic has been found in luoxuanxi Studio 0.6.26. This affects the function validatePath of the file /api/hermes/download of the component Download. The manipulation leads to path traversal.

This vulnerability is documented as CVE-2026-67918. The attack can be initiated remotely. There is not any exploit available.