A vulnerability identified as critical has been detected in Dromara lamp-cloud up to 5.10.0 . This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller . Performing a manipulation of the argument bucket/bizType results in path traversal. This vulnerability is identified as CVE-2026-19757 . The attack can be initiated remotely. Additionally, an exploit exists. The project was informed of the problem early through an issue report but has