CVE-2026-53777
Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any locatio
CVSS
8.1
Alto
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Publicado: 11 jun 2026 · Última mod.: 14 jul 2026 · CWE-22
Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact_name or download_path fields, causing the client to overwrite sensitive files or expose arbitrary local files to an attacker-accessible location.
- github.comhttps://github.com/PerryTS/perry/commit/95e1043df8081f67038bffce847dd9ddb3dae046
- github.comhttps://github.com/PerryTS/perry/pull/4989
- github.comhttps://github.com/PerryTS/perry/releases/tag/v0.5.1159
- github.comhttps://github.com/PerryTS/perry/security/advisories/GHSA-x55v-q459-68ch
- www.vulncheck.comhttps://www.vulncheck.com/advisories/perry-path-traversal-via-artifactready-websocket
- github.comhttps://github.com/PerryTS/perry/security/advisories/GHSA-x55v-q459-68ch