A vulnerability identified as critical has been detected in aehrc Pathling up to 1.x. This affects the function
$import-pnp of the component Import PNP Operation. This manipulation of the argument exportUrl causes improper input validation.
The identification of this vulnerability is CVE-2026-47664. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.