Sceawere

Vulnerability Detail

CVE-2026-102810UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Marmite Path Traversal Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
rochacbruno
Product
marmite
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable by the marmite process.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T18:17:14.370Z",
  "pubdate": "2026-09-29T18:17:14.370Z",
  "executiveSummary": "Marmite versions through 0.4.2 are susceptible to a critical path traversal vulnerability within the integrated development server, initiated via the --serve flag.\nThis security flaw allows unauthenticated remote attackers to bypass intended directory restrictions and read arbitrary files located on the host filesystem with the privileges of the Marmite process.\nThe vulnerability arises from improper input validation within the request handling logic, where insufficient sanitization of percent-encoded path segments facilitates unauthorized access.\nThe risk is significant, as it grants attackers the capability to exfiltrate sensitive configuration files, source code, or system information without requiring prior authentication.\nThis flaw is exploitable over the network by any entity capable of reaching the development server, posing a severe risk to environments where Marmite is deployed in an insecure or publicly accessible state.",
  "technicalDetails": "The vulnerability is localized within the handle_request function located in src/server.rs of the Marmite codebase. The root cause is an inadequate implementation of path normalization and validation logic when processing incoming HTTP requests.\nSpecifically, the server performs percent-decoding on the requested URI path before concatenating it with the designated output directory. However, the application fails to verify or strip directory traversal sequences (e.g., '../') post-decoding. By injecting encoded sequences (such as %2e%2e%2f) into the request path, an attacker can escape the intended root directory context defined for the server.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP GET request to the Marmite development server. The request includes a URI designed with malicious path segments. Because the handle_request function improperly handles these segments during the file resolution process, the server-side code joins the malicious path with the base output directory, resulting in a resolved path that points to sensitive locations outside the intended root. The server then reads the file at the resolved path and returns the contents to the attacker.\nThis vulnerability is classified as a classic path traversal attack. Because the server does not enforce a strict whitelist or canonicalization check, it blindly trusts the input provided by the client. The exploitation does not require authentication, meaning the impact is immediate upon connection to the --serve instance. The scope of the exfiltrated data is strictly limited to files currently readable by the OS user executing the Marmite process.\nBecause the server uses a naive concatenation approach, any file residing on the filesystem that possesses read permissions for the Marmite service account is exposed. This includes, but is not limited to, system configuration files, environmental variables, or other sensitive artifacts within the development environment. The vulnerability affects all versions of Marmite up to and including 0.4.2."
}
CVE-2026-102810: Marmite Path Traversal Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere