A vulnerability categorized as critical has been discovered in Dromara lamp-cloud up to 5.10.0 . This affects an unknown part of the file DefGenProjectController.java of the component Code Generator . Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. This vulnerability is referenced as CVE-2026-19756 . It is possible to launch the attack remotely. Furthermore, an exploit is available. The project was informed of the problem early through an issue report bu