Impact
A path traversal flaw in cube‑root/directory‑serve permits a remote attacker who does not need to authenticate to delete files that reside outside the intended directory when the application is run with the '--delete' option. The flaw exists because the file path supplied by the attacker is not sufficiently confined, allowing traversal via '../' sequences. As a result, an attacker can remove critical files, compromise data integrity, or disrupt service availability.
Affected Systems
The affected product is cube‑root:directory‑serve, affecting all releases through version 1.3.7. No other vendors or versions are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 9.1, indicating a high severity level. Exploitation requires no authentication and relies on straightforward input manipulation by an unauthenticated remote attacker. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the combination of a high CVSS score and a simple exploitation vector suggests a notably high risk to systems running vulnerable versions.
OpenCVE Enrichment