Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations. | |
| Title | rustypaste before 0.18.1 Path Traversal via filename header | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:44.589Z
Reserved: 2026-09-13T10:14:58.756Z
Link: CVE-2026-90774
No data.
Status : Received
Published: 2026-09-13T11:17:02.163
Modified: 2026-09-13T11:17:02.163
Link: CVE-2026-90774
No data.
OpenCVE Enrichment
No data.
