A vulnerability, which was classified as critical, has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. The manipulation of the argument File leads to path traversal.

This vulnerability is listed as CVE-2026-19761. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.