Impact
The vulnerability in rustypaste is a path traversal flaw that occurs when the server applies an optional custom filename HTTP header after validating the destination path. Attackers can specify path traversal sequences in the header, enabling the application to write files outside the configured upload directory and to arbitrary locations on the host filesystem. This defect permits modification or creation of files on the system, potentially enabling further compromise or persistence, and is specifically a CWE‑22 type file and directory traversal weakness.
Affected Systems
rustypaste, built by orhun, is affected on all releases older than 0.18.1. The fix was introduced in version 0.18.1; any instance running a prior version with the optional filename header enabled is vulnerable.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. The EPSS score is listed as less than 1%, indicating a very low but nonzero exploitation probability at the time of analysis. The vulnerability is not cataloged in CISA KEV. It is inferred that an attacker only needs to send a crafted HTTP request containing a malicious filename header to exploit required, so publicly exposed instances are at risk. The attack exposed rustypaste instance, inserting directory traversal characters in the filename header to place a file wherever the web server process can write. Because the flaw bypasses the path validation, the attacker achieves arbitrary file write.
OpenCVE Enrichment