Vendor
rustypaste versions prior to 0.18.1 contain a path traversal vulnerability that allows attackers to write files to arbitrary locations by manipulating the custom filename HTTP header.