Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-13716 represents a critical path traversal vulnerability in Crafty Controller's server import and admin file upload functionality. With a CVSS score of 9.1, this vulnerability allows authenticated attackers to bypass directory restrictions and write files to arbitrary locations on the system where the Crafty Controller application has permissions. This is particularly dangerous because it enables remote code execution—an attacker can upload malicious scripts or executables and execute them with the privileges of the Crafty Controller process. Organizations running Crafty Controller for game server management, infrastructure orchestration, or similar purposes face immediate risk of complete system compromise through this authenticated but easily exploitable flaw.
While this CVE maps to CWE-35 (Path Traversal) rather than specific MITRE ATT&CK techniques, Casky's Claude-powered analysis engine would identify the attack chain spanning multiple technique categories: T1190 (Exploit Public-Facing Application) for initial exploitation, T1078 (Valid Accounts) for leveraging authenticated access, and T1190/T1567 patterns associated with file upload abuse. Practitioners using Casky would observe detection findings highlighting suspicious file upload patterns with path traversal indicators (../, absolute paths, encoded traversal sequences), anomalous file creation in unexpected system directories, and execution of uploaded content. The extended reasoning capability would correlate these signals to map the complete attack progression from authentication through privilege escalation, enabling defenders to identify and respond to exploitation attempts before code execution occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-13716. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation