Bold Reports Standalone Report Designer Path Traversal Vulnerability
A critical vulnerability in Bold Reports Standalone Report Designer versions before 14.1.12 allows unauthenticated attackers to read arbitrary files from the server filesystem, potentially disclosing sensitive information.
What happened
Bold Reports Standalone Report Designer before version 14.1.12 contains a missing filepath validation vulnerability in its SVG, font, and database download features. This path traversal weakness enables unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this to disclose sensitive server files, including authentication credentials, leading to full unauthorized access to the application.
The vulnerability is tracked as CVE-2026-65687, CVE-2026-65688, and CVE-2026-65689, all rated CRITICAL with a CVSS score of 9.8. The recommended action is to upgrade to Bold Reports Standalone Report Designer version 14.1.12 or later.
Affected components include bold reports standalone report designer (npm) versions prior to 14.1.12. For more detailed information, consult the primary sources: [CVE-2026-65687](https://nvd.nist.gov/vuln/detail/CVE-2026-65687), [CVE-2026-65688](https://nvd.nist.gov/vuln/detail/CVE-2026-65688), and [CVE-2026-65689](https://nvd.nist.gov/vuln/detail/CVE-2026-65689).
How 0Day mitigates this
bold reports standalone report designer is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.