<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Marmite - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/marmite/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 18:29:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/marmite/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal in Marmite Development Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-marmite-path-traversal/</link><pubDate>Tue, 29 Sep 2026 18:29:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-marmite-path-traversal/</guid><description>Marmite versions 0.4.2 and earlier contain a path traversal vulnerability in the --serve development server allowing unauthenticated attackers to read arbitrary files.</description><content:encoded><![CDATA[<p>Marmite versions 0.4.2 and earlier contain a path traversal vulnerability within the development server component, activated when the application is executed with the --serve flag. The vulnerability resides in the handle_request function within src/server.rs. The application performs insufficient validation on requested file paths, specifically failing to properly handle or neutralize directory traversal sequences (such as ../) after undergoing percent-decoding.</p>
<p>This flaw allows an unauthenticated remote attacker to construct malicious HTTP requests containing encoded traversal sequences. When processed, these requests enable the attacker to escape the designated web root and access arbitrary files on the host file system. The scope of accessible files is restricted only by the permissions of the user account running the Marmite process. Given the vulnerability exists within a development server implementation, it poses a significant risk to developers and build environments where such components might be exposed to internal networks or local interfaces.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to read sensitive configuration files, source code, credentials, or other system data residing on the server. In typical development environments, this could lead to the exposure of environment variables or database connection strings, facilitating further compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and remediation of Marmite instances in development environments.</p>
<ul>
<li>Upgrade Marmite to a patched version beyond 0.4.2 once available.</li>
<li>Audit development environments using Marmite for exposure to untrusted networks.</li>
<li>Restrict access to the Marmite development server (started via --serve) to localhost only, using binding flags such as --host 127.0.0.1.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>path-traversal</category></item></channel></rss>