Impact
Perspective 5.0.0 contains a path traversal flaw in the cwd_static_file_handler that lets unauthenticated attackers include literal "../" segments in HTTP request URLs. The flaw bypasses insufficient query‑string sanitization, enabling traversal outside the configured asset root. Attackers can then read arbitrary files on the server filesystem, such as system credentials and application secrets, with the results exposed cross‑origin because a wildcard Access‑Control-Allow-Origin header is applied to every response.
Affected Systems
The vulnerable product is Perspective by perspective‑dev, version 5.0.0. Any installation running this exact release is affected; no other versions or backports are listed as impacted.
Risk and Exploitability
The CVSS score of 8.7 marks this vulnerability as High, and its EPSS score is currently unavailable, indicating no quantified exploitation frequency. The vulnerability is not listed in CISA KEV, but its capability to read arbitrary files coupled with an open web interface means the likelihood of exploitation in the wild remains significant. Attackers can achieve confidential data disclosure simply by making a crafted HTTP request; no authentication or privilege escalation is required and the attack can be performed remotely.
OpenCVE Enrichment