Impact
An authenticated operator can exploit a path traversal flaw in Sliver's website content subsystem to read arbitrary files from the server host, potentially exposing credentials, configuration data, and cryptographic keys. This flaw undermines data confidentiality and could allow an attacker to gather sensitive information that might be used for further attacks.
Affected Systems
The vulnerability affects the Sliver command and control framework distributed by BishopFox. All releases before version 1.6.11 are susceptible; the issue is fixed in version 1.6.11 and later.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers must be authenticated operators with web access to the content subsystem; they can then specify a path containing ..\ characters to read any file on the host file system.
OpenCVE Enrichment
Github GHSA