EspoCRM Relative Path Traversal Vulnerability - CVE-2026-33733
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4 the admin template management endpoints accept attacker-controlled name and scope values and pass them into template path construction without normalization or traversal filtering. As a result an authenticated admin can use ../ sequences to escape the intended template directory and read create overwrite or delete arbitrary files that resolve to body.tpl or subject.tpl under the web application user39s filesystem permissions. Version 9.3.4 fixes the issue.