A vulnerability labeled as critical has been found in dromara lamp-cloud up to 5.10.0 . This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint . Executing a manipulation of the argument Name can lead to path traversal. This vulnerability is tracked as CVE-2026-19758 . The attack can be launched remotely. Moreover, an exploit is present. The project was informed of the problem early through an issue report but has not responded yet.