Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orhun
Orhun rustypaste |
|
| Vendors & Products |
Orhun
Orhun rustypaste |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations. | |
| Title | rustypaste before 0.18.1 Path Traversal via filename header | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T15:35:22.769Z
Reserved: 2026-09-13T10:14:58.756Z
Link: CVE-2026-90774
Updated: 2026-09-14T15:35:18.469Z
Status : Received
Published: 2026-09-13T11:17:02.163
Modified: 2026-09-14T16:17:39.350
Link: CVE-2026-90774
No data.
OpenCVE Enrichment
Updated: 2026-09-17T19:47:33Z