Chonkie · Littrs · CVE-2026-97365
**Name of the Vulnerable Software and Affected Versions**
chonkie-inc littrs versions 0.6.1 through 0.6.2
**Description**
A remote path traversal issue exists in the `Sandbox::mount()` function within the `crates/littrs/src/lib.rs` file. This occurs when the `relative` argument is manipulated, allowing an attacker to access files or directories outside the intended scope.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict or avoid the use of the `Sandbox::mount()` function.