Sceawere
Vulnerability Detail
CVE-2026-102810UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Marmite Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 7h ago
- Vendor
- rochacbruno
- Product
- marmite
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable by the marmite process.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-29T18:17:14.370Z",
"pubdate": "2026-09-29T18:17:14.370Z",
"executiveSummary": "Marmite versions through 0.4.2 are susceptible to a critical path traversal vulnerability within the integrated development server, initiated via the --serve flag.\nThis security flaw allows unauthenticated remote attackers to bypass intended directory restrictions and read arbitrary files located on the host filesystem with the privileges of the Marmite process.\nThe vulnerability arises from improper input validation within the request handling logic, where insufficient sanitization of percent-encoded path segments facilitates unauthorized access.\nThe risk is significant, as it grants attackers the capability to exfiltrate sensitive configuration files, source code, or system information without requiring prior authentication.\nThis flaw is exploitable over the network by any entity capable of reaching the development server, posing a severe risk to environments where Marmite is deployed in an insecure or publicly accessible state.",
"technicalDetails": "The vulnerability is localized within the handle_request function located in src/server.rs of the Marmite codebase. The root cause is an inadequate implementation of path normalization and validation logic when processing incoming HTTP requests.\nSpecifically, the server performs percent-decoding on the requested URI path before concatenating it with the designated output directory. However, the application fails to verify or strip directory traversal sequences (e.g., '../') post-decoding. By injecting encoded sequences (such as %2e%2e%2f) into the request path, an attacker can escape the intended root directory context defined for the server.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP GET request to the Marmite development server. The request includes a URI designed with malicious path segments. Because the handle_request function improperly handles these segments during the file resolution process, the server-side code joins the malicious path with the base output directory, resulting in a resolved path that points to sensitive locations outside the intended root. The server then reads the file at the resolved path and returns the contents to the attacker.\nThis vulnerability is classified as a classic path traversal attack. Because the server does not enforce a strict whitelist or canonicalization check, it blindly trusts the input provided by the client. The exploitation does not require authentication, meaning the impact is immediate upon connection to the --serve instance. The scope of the exfiltrated data is strictly limited to files currently readable by the OS user executing the Marmite process.\nBecause the server uses a naive concatenation approach, any file residing on the filesystem that possesses read permissions for the Marmite service account is exposed. This includes, but is not limited to, system configuration files, environmental variables, or other sensitive artifacts within the development environment. The vulnerability affects all versions of Marmite up to and including 0.4.2."
}