{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/vanna--2.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-65702"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vanna \u003c= 2.0.2"],"_cs_severities":["high"],"_cs_tags":["path-traversal","file-write","file-read","vulnerability","web-application","cve"],"_cs_type":"advisory","_cs_vendors":["Vanna"],"content_html":"\u003cp\u003eA critical path traversal vulnerability, tracked as CVE-2026-65702, has been identified in Vanna through version 2.0.2. This flaw resides within the \u003ccode\u003eFileSystemConversationStore\u003c/code\u003e persistence integration, which is responsible for storing conversation metadata. Unauthenticated remote attackers can exploit this vulnerability by manipulating the \u003ccode\u003econversation_id\u003c/code\u003e parameter within requests sent to Vanna's unauthenticated chat API endpoints. By injecting path traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e, \u003ccode\u003e..\\\u003c/code\u003e), attackers can escape the intended base directory. This allows them to perform arbitrary file write operations, injecting attacker-controlled JSON content into any location on the server's filesystem. Furthermore, the same mechanism enables unauthorized file read operations, allowing attackers to access conversation metadata or other sensitive files located outside the designated storage directory, potentially leading to data exfiltration or further system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated remote attacker identifies a Vanna instance running version 2.0.2 or earlier, exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request, targeting Vanna's unauthenticated chat API endpoints.\u003c/li\u003e\n\u003cli\u003eIn the crafted request, the attacker includes path traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e, \u003ccode\u003e..\\\u003c/code\u003e, or their URL-encoded equivalents) within the \u003ccode\u003econversation_id\u003c/code\u003e parameter in the URL query string.\u003c/li\u003e\n\u003cli\u003eFor arbitrary file \u003cem\u003ewrite\u003c/em\u003e operations, the attacker includes attacker-controlled JSON content within the request body (typically a POST request). The manipulated \u003ccode\u003econversation_id\u003c/code\u003e dictates the arbitrary filesystem path where this JSON content will be written.\u003c/li\u003e\n\u003cli\u003eFor arbitrary file \u003cem\u003eread\u003c/em\u003e operations, the attacker submits a request where the \u003ccode\u003econversation_id\u003c/code\u003e parameter is set to a path traversal sequence leading to a target file (e.g., \u003ccode\u003econversation_id=../../../../etc/passwd\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eVanna's \u003ccode\u003eFileSystemConversationStore\u003c/code\u003e component processes the request and incorrectly resolves the manipulated \u003ccode\u003econversation_id\u003c/code\u003e parameter, failing to properly sanitize the input.\u003c/li\u003e\n\u003cli\u003eThis misinterpretation results in the server either writing the attacker-controlled JSON file to an arbitrary location on the filesystem or reading the content of the specified arbitrary file from the server's filesystem.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully writes malicious content (e.g., a web shell) or exfiltrates sensitive data read from the system, potentially leading to remote code execution or complete system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-65702 allows unauthenticated attackers to achieve arbitrary file write and read capabilities on the vulnerable Vanna server. This directly translates to significant risks, including unauthorized data exposure, system tampering, and potential remote code execution (RCE) if the attacker can write a web shell or overwrite critical system files. Organizations using vulnerable Vanna versions are at risk of complete system compromise, data breaches, and service disruption. The impact is critical due to the unauthenticated nature of the vulnerability and the broad capabilities it grants to an attacker, affecting the integrity, confidentiality, and availability of the affected system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65702 immediately by upgrading Vanna to a version greater than 2.0.2.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM to detect exploitation attempts against Vanna's chat API endpoints, specifically looking for \u003ccode\u003econversation_id\u003c/code\u003e parameters containing path traversal sequences in web server logs.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs (category \u003ccode\u003ewebserver\u003c/code\u003e) for HTTP requests containing suspicious path traversal indicators, especially within query parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T18:29:58Z","date_published":"2026-07-23T18:29:58Z","id":"https://feed.craftedsignal.io/briefs/2026-07-vanna-path-traversal/","summary":"Vanna versions up to and including 2.0.2 contain a path traversal vulnerability in its FileSystemConversationStore persistence integration, allowing unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary server filesystem locations and read conversation metadata or other files from outside the intended base directory by supplying path traversal sequences within the 'conversation_id' parameter to unauthenticated chat API endpoints.","title":"Vanna FileSystemConversationStore Path Traversal Vulnerability (CVE-2026-65702)","url":"https://feed.craftedsignal.io/briefs/2026-07-vanna-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Vanna \u003c= 2.0.2","version":"https://jsonfeed.org/version/1.1"}