CVE-2026-90774

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.

Scoring

Severity
HIGH
CVSS base score
8.7
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.38%
CWE
CWE-22
Published
2026-09-13
Last modified
2026-09-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs