Rochacbruno · Marmite · CVE-2026-102811
Marmite through 0.4.2 contains missing authentication in the development server endpoints / marmite /content, / marmite /config, and / marmite /file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle create content and handle clone content to write files outside the project directory via directory traversal.