Path Traversal in Marmite Development Server
Marmite versions 0.4.2 and earlier contain a path traversal vulnerability in the --serve development server allowing unauthenticated attackers to read arbitrary files.
CVE search metadata
CVE search record: CVE-2026-102810. Severity: high. CVSS: 7.5. KEV: no. Product: Marmite (<= 0.4.2). Brief: Path Traversal in Marmite Development Server. Brief link: https://feed.craftedsignal.io/briefs/2026-09-marmite-path-traversal/
Marmite versions 0.4.2 and earlier contain a path traversal vulnerability within the development server component, activated when the application is executed with the --serve flag. The vulnerability resides in the handle_request function within src/server.rs. The application performs insufficient validation on requested file paths, specifically failing to properly handle or neutralize directory traversal sequences (such as ../) after undergoing percent-decoding.
This flaw allows an unauthenticated remote attacker to construct malicious HTTP requests containing encoded traversal sequences. When processed, these requests enable the attacker to escape the designated web root and access arbitrary files on the host file system. The scope of accessible files is restricted only by the permissions of the user account running the Marmite process. Given the vulnerability exists within a development server implementation, it poses a significant risk to developers and build environments where such components might be exposed to internal networks or local interfaces.
Impact
Successful exploitation allows unauthenticated attackers to read sensitive configuration files, source code, credentials, or other system data residing on the server. In typical development environments, this could lead to the exposure of environment variables or database connection strings, facilitating further compromise.
Recommendation
Prioritize the identification and remediation of Marmite instances in development environments.
- Upgrade Marmite to a patched version beyond 0.4.2 once available.
- Audit development environments using Marmite for exposure to untrusted networks.
- Restrict access to the Marmite development server (started via --serve) to localhost only, using binding flags such as --host 127.0.0.1.
Immediate actions
Inventory all systems running Marmite <= 0.4.2
Deploy Sigma detection rule for path traversal patterns
Mitigations
Bind --serve to 127.0.0.1 on affected servers
CVE-2026-102810
Detection coverage 1
Detect CVE-2026-102810 Path Traversal Attempt
highDetects path traversal attempts against the Marmite development server by identifying percent-encoded traversal sequences in URI requests
Detection queries are available on the platform. Get full rules →