Skip to content
Threat Feed
high advisory

Path Traversal in Marmite Development Server

Marmite versions 0.4.2 and earlier contain a path traversal vulnerability in the --serve development server allowing unauthenticated attackers to read arbitrary files.

CVE search metadata

CVE search record: CVE-2026-102810. Severity: high. CVSS: 7.5. KEV: no. Product: Marmite (<= 0.4.2). Brief: Path Traversal in Marmite Development Server. Brief link: https://feed.craftedsignal.io/briefs/2026-09-marmite-path-traversal/

Marmite versions 0.4.2 and earlier contain a path traversal vulnerability within the development server component, activated when the application is executed with the --serve flag. The vulnerability resides in the handle_request function within src/server.rs. The application performs insufficient validation on requested file paths, specifically failing to properly handle or neutralize directory traversal sequences (such as ../) after undergoing percent-decoding.

This flaw allows an unauthenticated remote attacker to construct malicious HTTP requests containing encoded traversal sequences. When processed, these requests enable the attacker to escape the designated web root and access arbitrary files on the host file system. The scope of accessible files is restricted only by the permissions of the user account running the Marmite process. Given the vulnerability exists within a development server implementation, it poses a significant risk to developers and build environments where such components might be exposed to internal networks or local interfaces.

Impact

Successful exploitation allows unauthenticated attackers to read sensitive configuration files, source code, credentials, or other system data residing on the server. In typical development environments, this could lead to the exposure of environment variables or database connection strings, facilitating further compromise.

Recommendation

Prioritize the identification and remediation of Marmite instances in development environments.

  • Upgrade Marmite to a patched version beyond 0.4.2 once available.
  • Audit development environments using Marmite for exposure to untrusted networks.
  • Restrict access to the Marmite development server (started via --serve) to localhost only, using binding flags such as --host 127.0.0.1.

Immediate actions

Inventory all systems running Marmite <= 0.4.2

IT Operations 48h

Deploy Sigma detection rule for path traversal patterns

Detection Engineering 72h

Mitigations

Bind --serve to 127.0.0.1 on affected servers

immediate IT Operations

CVE-2026-102810

Detection coverage 1

Detect CVE-2026-102810 Path Traversal Attempt

high

Detects path traversal attempts against the Marmite development server by identifying percent-encoded traversal sequences in URI requests

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →