Sceawere
Vulnerability Detail
CVE-2026-102811UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Marmite Unauthorized File Manipulation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 7h ago
- Vendor
- rochacbruno
- Product
- marmite
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-29T18:17:14.527Z",
"pubdate": "2026-09-29T18:17:14.527Z",
"executiveSummary": "Marmite versions up to 0.4.2 are susceptible to critical unauthorized file system access due to missing authentication controls on development server endpoints.\nThe vulnerability encompasses improper access control and directory traversal flaws, which collectively permit unauthenticated remote attackers to modify, create, and overwrite arbitrary files and site configurations.\nImpacted components include the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/. By leveraging unsanitized path parameters within internal handling functions, an adversary can escape the intended application directory scope.\nThe risk is severe as it enables full control over the application's configuration and content, potentially leading to remote code execution, site defacement, or total application compromise.\nNo authentication or specific privileges are required for exploitation, as the development server endpoints lack protective access mechanisms, making the system highly vulnerable to unauthorized network-based actors.",
"technicalDetails": "The vulnerability resides within the Marmite development server, which exposes sensitive administrative endpoints to unauthenticated users. Specifically, the endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/ lack any form of authentication middleware or access control validation, allowing any network-connected actor to interact with system management functions.\nThe root cause of the arbitrary file write capability stems from the insufficient sanitization of path parameters utilized by the functions handle_create_content and handle_clone_content. These functions are designed to manage site content but fail to enforce directory containment, facilitating directory traversal attacks (e.g., using '../' sequences).\nExploitation follows a predictable flow: An unauthenticated attacker sends crafted HTTP requests to the identified /__marmite__/ endpoints. By manipulating the path parameters within these requests, the attacker can break out of the intended project directory structure. Because the server process typically runs with the permissions of the user executing the application, the attacker gains the ability to overwrite or create files in any location accessible to that user.\nIn a typical attack scenario, an adversary could modify the site's configuration files (via /__marmite__/config) to alter application behavior, or overwrite existing content files (via /__marmite__/content) to inject malicious scripts or deface the platform. Furthermore, the ability to write to arbitrary file paths implies that an attacker could potentially overwrite sensitive system files, configuration files for other services, or drop web shells into the web root if the process environment permits.\nThis vulnerability is present in all Marmite versions through 0.4.2. Because the development server is intended for use in non-production environments, it often bypasses standard security review processes; however, if these endpoints are reachable via a network, the impact is equivalent to a remote administrative compromise. The lack of input validation on path-based parameters ensures that any attacker capable of reaching the development server can execute these malicious operations without any requirement for prior authentication or elevated privileges."
}