PT-2026-96326 · Dancer2 · Dancer2

CVE-2026-93712

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dancer2 versions 2.1.0 through 2.1.x
Description The File route handler allows the serving of files from outside the public dir directory through the use of relative path segments. This occurs because the handler joins the request path to the public dir without collapsing relative segments and only verifies if the resulting path is a readable regular file. An unauthenticated request using paths like /../outside.txt or percent-encoded dots can escape the intended directory to access any file readable by the worker process, such as the config.yml file. This issue affects applications that include File in route handlers and set static handler to 0.
Recommendations Update to version 2.2.0. As a temporary mitigation, avoid naming File in route handlers or ensure static handler is not set to 0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93712
GHSA-6XW8-V24C-M783

Affected Products

Dancer2