{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rustypaste/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rustypaste:rustypaste:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-90774"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rustypaste (\u003c 0.18.1)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","vulnerability","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["rustypaste"],"content_html":"\u003cp\u003erustypaste versions prior to 0.18.1 are affected by a path traversal vulnerability (CVE-2026-90774) stemming from improper input validation. The application validates the destination path before processing the optional custom filename header, which creates a race condition or logic flaw where the custom filename can contain directory traversal sequences (such as ../). This allows an attacker to bypass intended directory restrictions and write files outside of the configured upload directory. An unauthenticated attacker can exploit this to overwrite critical system configuration files or place malicious scripts (e.g., web shells) in executable directories, potentially leading to remote code execution or complete system compromise. This issue affects all rustypaste deployments using versions earlier than 0.18.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file write outside the designated upload directory. This could lead to a full system compromise if an attacker overwrites sensitive files or uploads malicious payloads to a location that is subsequently executed by the server or system processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all rustypaste instances to version 0.18.1 or later to remediate CVE-2026-90774.\u003c/li\u003e\n\u003cli\u003eReview server-side upload directory permissions to ensure the application runs with the least privilege necessary, minimizing the impact of potential file-write vulnerabilities.\u003c/li\u003e\n\u003cli\u003eAudit access logs for suspicious HTTP requests containing directory traversal sequences (e.g., '../') within custom headers or filename parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T11:26:13Z","date_published":"2026-09-13T11:26:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rustypaste-path-traversal/","summary":"rustypaste versions prior to 0.18.1 contain a path traversal vulnerability that allows attackers to write files to arbitrary locations by manipulating the custom filename HTTP header.","title":"Path Traversal Vulnerability in rustypaste","url":"https://feed.craftedsignal.io/briefs/2026-09-rustypaste-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Rustypaste","version":"https://jsonfeed.org/version/1.1"}