Sceawere
Vulnerability Detail
CVE-2026-105144UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Drogon Static File Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- n/a
- Product
- Drogon
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static File Router. Executing a manipulation can lead to path traversal. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-04T09:16:39.437Z",
"pubdate": "2026-10-04T09:16:39.437Z",
"executiveSummary": "A path traversal vulnerability exists in the StaticFileRouter component of the Drogon web framework, specifically affecting versions up to 1.9.13-1 and 10.0-beta.3 on the Windows operating system.\nThe vulnerability originates from improper neutralization of directory traversal sequences within the StaticFileRouter::route function, allowing remote, unauthenticated attackers to access arbitrary files outside the intended web root directory.\nSuccessful exploitation permits unauthorized read access to sensitive system files, potentially exposing configuration files, credentials, or source code residing on the underlying Windows host.\nGiven that public exploit material is available and the vendor has not addressed the disclosure, the risk of exploitation is elevated for internet-facing Drogon instances running on Windows.\nThe attack vector is purely remote and does not require prior authentication, making it a high-severity entry point for further system compromise.",
"technicalDetails": "The vulnerability resides within the StaticFileRouter::route function located in lib/src/StaticFileRouter.cc. The component is responsible for mapping incoming HTTP requests to static files served by the Drogon framework.\nThe root cause is an insufficient validation of user-supplied input paths. When processing requests on Windows, the router fails to adequately sanitize or normalize path strings containing directory traversal sequences, such as '..\\' or '../'.\nOn Windows systems, path resolution differences and the handling of both forward slashes and backslashes can create disparities between the intended path restriction and the actual file system access performed by the underlying OS API.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP GET request to the Drogon server. This request includes a URI path containing traversal sequences (e.g., /static/../../windows/win.ini). The StaticFileRouter::route function receives this input and fails to correctly strip or validate the path traversal patterns before passing the concatenated path to the file system API.\nBecause the function does not verify that the resulting canonicalized path remains within the defined document root, the file system API treats the traversal sequences as instructions to move up the directory tree. This allows the attacker to break out of the static file directory.\nAs the exploit is remote and does not require authentication, an attacker can enumerate the file system iteratively. The vulnerability is categorized as a path traversal attack, which is inherently dangerous in web environments as it bypasses application-level access controls.\nPost-exploitation impact includes the unauthorized retrieval of any file accessible to the process running the Drogon service. On Windows, this is particularly critical as file system access controls may be bypassed if the service is running with high privileges, potentially leading to a full information disclosure scenario. The existence of a published exploit significantly lowers the barrier to entry for malicious actors, necessitating immediate defensive focus."
}