{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/marmite/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:marmite:marmite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-102810"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Marmite (\u003c= 0.4.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal"],"_cs_type":"advisory","_cs_vendors":["Marmite"],"content_html":"\u003cp\u003eMarmite versions 0.4.2 and earlier contain a path traversal vulnerability within the development server component, activated when the application is executed with the --serve flag. The vulnerability resides in the handle_request function within src/server.rs. The application performs insufficient validation on requested file paths, specifically failing to properly handle or neutralize directory traversal sequences (such as ../) after undergoing percent-decoding.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an unauthenticated remote attacker to construct malicious HTTP requests containing encoded traversal sequences. When processed, these requests enable the attacker to escape the designated web root and access arbitrary files on the host file system. The scope of accessible files is restricted only by the permissions of the user account running the Marmite process. Given the vulnerability exists within a development server implementation, it poses a significant risk to developers and build environments where such components might be exposed to internal networks or local interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read sensitive configuration files, source code, credentials, or other system data residing on the server. In typical development environments, this could lead to the exposure of environment variables or database connection strings, facilitating further compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and remediation of Marmite instances in development environments.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Marmite to a patched version beyond 0.4.2 once available.\u003c/li\u003e\n\u003cli\u003eAudit development environments using Marmite for exposure to untrusted networks.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Marmite development server (started via --serve) to localhost only, using binding flags such as --host 127.0.0.1.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T18:29:30Z","date_published":"2026-09-29T18:29:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-marmite-path-traversal/","summary":"Marmite versions 0.4.2 and earlier contain a path traversal vulnerability in the --serve development server allowing unauthenticated attackers to read arbitrary files.","title":"Path Traversal in Marmite Development Server","url":"https://feed.craftedsignal.io/briefs/2026-09-marmite-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Marmite","version":"https://jsonfeed.org/version/1.1"}