PT-2026-96326 · Dancer2 · Dancer2
CVE-2026-93712
·
Published
2026-09-22
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dancer2 versions 2.1.0 through 2.1.x
Description
The File route handler allows the serving of files from outside the
public dir directory through the use of relative path segments. This occurs because the handler joins the request path to the public dir without collapsing relative segments and only verifies if the resulting path is a readable regular file. An unauthenticated request using paths like /../outside.txt or percent-encoded dots can escape the intended directory to access any file readable by the worker process, such as the config.yml file. This issue affects applications that include File in route handlers and set static handler to 0.Recommendations
Update to version 2.2.0.
As a temporary mitigation, avoid naming File in
route handlers or ensure static handler is not set to 0.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dancer2