CVE-2026-90774
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
Faiblesse
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
Références
- https://github.com/orhun/rustypaste
- https://github.com/orhun/rustypaste/blob/v0.18.0/src/paste.rs
- https://github.com/orhun/rustypaste/commit/ac05d552596af4a8429d80f30d11f67117ce02c8
- https://github.com/orhun/rustypaste/issues/622
- https://www.vulncheck.com/advisories/rustypaste-before-0.18.1-path-traversal-via-filename-header
- https://github.com/orhun/rustypaste/issues/622
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.