CVE-2026-58192Appium · Appium\/storage-plugin
Vulnerability data via NVD (ingested)
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to escape the storage root with ../ sequences and recursively delete arbitrary writable files or directories. This issue is fixed in version 1.1.6.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-58192product:"Appium Appium\/storage-plugin"http.html:"Appium\/storage-plugin"More intel sources (5)
vuln:CVE-2026-58192vulnerabilities.cve_id: CVE-2026-58192CVE-2026-58192CVE-2026-58192"CVE-2026-58192" exploit -site:nvd.nist.gov