Description
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
Published: 2026-09-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Path traversal allowing arbitrary file writes
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in rustypaste is a path traversal flaw that occurs when the server applies an optional custom filename HTTP header after validating the destination path. Attackers can specify path traversal sequences in the header, enabling the application to write files outside the configured upload directory and to arbitrary locations on the host filesystem. This defect permits modification or creation of files on the system, potentially enabling further compromise or persistence, and is specifically a CWE‑22 type file and directory traversal weakness.

Affected Systems

rustypaste, built by orhun, is affected on all releases older than 0.18.1. The fix was introduced in version 0.18.1; any instance running a prior version with the optional filename header enabled is vulnerable.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. The EPSS score is listed as less than 1%, indicating a very low but nonzero exploitation probability at the time of analysis. The vulnerability is not cataloged in CISA KEV. It is inferred that an attacker only needs to send a crafted HTTP request containing a malicious filename header to exploit required, so publicly exposed instances are at risk. The attack exposed rustypaste instance, inserting directory traversal characters in the filename header to place a file wherever the web server process can write. Because the flaw bypasses the path validation, the attacker achieves arbitrary file write.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rustypaste to version 0.18.1 or later to apply the path traversal fix (CWE‑22).
  • If an upgrade cannot be performed immediately, disable the optional custom filename HTTP header or constrain its allowed values to exclude traversal sequences.
  • Place the upload directory in a location with restrictive file permissions and implement server‑side checks to ensure the final file path remains within the intended directory structure.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Orhun
Orhun rustypaste
Vendors & Products Orhun
Orhun rustypaste

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
Title rustypaste before 0.18.1 Path Traversal via filename header
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Orhun Rustypaste
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:55.235Z

Reserved: 2026-09-13T10:14:58.756Z

Link: CVE-2026-90774

cve-icon Vulnrichment

Updated: 2026-09-14T15:35:18.469Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:02.163

Modified: 2026-09-23T17:17:47.507

Link: CVE-2026-90774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:33Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')