Impact
The flaw allows an attacker to manipulate the http_sendfile2 function in facil.io, enabling path traversal that can read files located outside the intended public directory. This results in unauthorized access to sensitive data that may reside on the file system, matching the path‑traversal weakness identified as CWE‑22. The vulnerability does not claim arbitrary code execution, but any read of executable configuration or code files could potentially lead to indirect compromise.
Affected Systems
The affected product is boazsegev facil.io, version 0.7.58 and earlier. Deployments of these releases are susceptible across all operating systems and hosting environments where the Public Folder Handler is exposed.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity, while the EPSS score of less than 1 % indicates a low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, yet publicly released exploit code is available. Attacks require remote access to the HTTP service that runs http_sendfile2, which is typically reachable over the Internet. The combination of a public exploit and potential for sensitive data disclosure makes the overall risk significant enough to warrant prompt action.
OpenCVE Enrichment