CVE-2026-90774
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypa
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 13, 2026 · Last modified: Sep 13, 2026 · CWE-22
Not enough EPSS history yet.
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
- github.comhttps://github.com/orhun/rustypaste
- github.comhttps://github.com/orhun/rustypaste/blob/v0.18.0/src/paste.rs
- github.comhttps://github.com/orhun/rustypaste/commit/ac05d552596af4a8429d80f30d11f67117ce02c8
- github.comhttps://github.com/orhun/rustypaste/issues/622
- www.vulncheck.comhttps://www.vulncheck.com/advisories/rustypaste-before-0.18.1-path-traversal-via-filename-header
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-904945.3 MED—
——0A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.1dCVE-2026-8570610.0 CRI65.0%
KEV—69GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability2dCVE-2026-90445—28.0%
——8An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.2dCVE-2026-498467.5 HIG27.4%
——8libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.2dCVE-2026-87910—35.8%
——11When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.2dCVE-2026-87984—36.2%
——11An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.2d