Impact
libks is the foundational library for Signalwire's C products, and its HTTP request parser includes a function named clean_uri(). As of versions before 2.0.11, clean_uri() does not reject URIs that contain more path segments than its internal canonicalization buffer can store. The canonicalization step silently passes these malformed URIs through while preserving embedded ".." sequences. When a consuming application later concatenates the URI to a filesystem path, an attacker can traverse directories outside the intended location. Because the vulnerability stems from the library itself, any application using libks before the 2.0.11 fix is susceptible to this path traversal flaw.
Affected Systems
Signalwire products that bundle libks prior to version 2.0.11 are vulnerable. The affected component provides foundational support for Signalwire C products.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity vulnerability, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector involves a service that incorporates libks. If the service subsequently appends the malformed URI to a file system path, the attacker could traverse outside the intended directory, leading to unauthorized file access or modification, subject to the privileges of the running process.
OpenCVE Enrichment