Impact
A path traversal flaw exists in the Sandbox::mount function of the littrs library version 0.6.1 and 0.6.2. By providing a specially crafted relative argument, an attacker can cause the program to mount or access directories outside the intended sandbox, potentially exposing confidential files or sensitive configuration data. The vulnerability is a classic present‑in‑path traversal (CWE-22) and could allow an adversary to read or manipulate files the application is not meant to access.
Affected Systems
The affected product is chonkie-inc:littrs, currently at versions 0.6.1 and 0.6.2. No other versions or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and no EPSS data is currently available. The vulnerability is not listed in CISA’s KEV catalog, but it is publicly disclosed and can be triggered remotely, which means an attacker with network access to the instance can exploit the flaw. Attackers would simply supply a malicious relative path to the mount endpoint to traverse directories, suggesting a low barrier to exploitation given a reachable interface.
OpenCVE Enrichment