A vulnerability was found in GeneralSandman TinyWeb up to 0.0.8 and classified as problematic. The impacted element is the function HttpBuilder::buildResponse of the component URL parser. The manipulation results in path traversal.

This vulnerability is known as CVE-2026-67185. It is possible to launch the attack remotely. No exploit is available.

It is advisable to implement a patch to correct this issue.