PT-2026-64044 · Meshery · Meshery
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Meshery versions prior to 1.0.57
Description
An unauthenticated arbitrary file read issue exists in the '/api/system/fileView' and '/api/system/fileDownload' endpoints. The system passes user-supplied
file parameters directly to the os.Open() function without performing path validation. This allows attackers to use absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.Recommendations
Update to version 1.0.57 or later.
As a temporary mitigation, restrict access to the '/api/system/fileView' and '/api/system/fileDownload' endpoints.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meshery