# CVE-2026-90774

## Summary

- **CVE ID:** CVE-2026-90774
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-22
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 14, 2026

## Description

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.

## Affected Products

- orhun — rustypaste (0)

## References

- [CNA](https://github.com/orhun/rustypaste/issues/622)
- [CNA](https://github.com/orhun/rustypaste)
- [CNA](https://github.com/orhun/rustypaste/blob/v0.18.0/src/paste.rs)
- [CNA](https://github.com/orhun/rustypaste/commit/ac05d552596af4a8429d80f30d11f67117ce02c8)
- [CNA](https://www.vulncheck.com/advisories/rustypaste-before-0.18.1-path-traversal-via-filename-header)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 32.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._