CVE-2026-102810 Details
Description
Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable by the marmite process.
A path traversal vulnerability has been identified in Marmite versions through 0.4.2. This vulnerability exists in the development server when started with the '--serve' option, allowing unauthenticated attackers to read arbitrary files. The issue arises because the 'handle_request' function in 'src/server.rs' does not properly validate '..' segments after percent-decoding the request URL. This oversight enables attackers to craft requests that traverse directories and access files that the Marmite process can read.
Users can update to Marmite version 0.4.3, which addresses the path traversal vulnerability by defaulting the '--serve' option to '127.0.0.1:8000' and preserving the requested interface when falling back to an OS-assigned port.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rochacbruno/marmite | [email protected] | ProductVendor |
| https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/server.rs#L180-L315 | [email protected] | Source CodeVendor |
| https://github.com/rochacbruno/marmite/commit/303a0bf2fff4302f4164c0c39932fdffc6683ad4 | [email protected] | Source CodeVendor |
| https://github.com/rochacbruno/marmite/issues/554 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/marmite-through-0.4.2-path-traversal-via-development-server | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Marmite | <= 0.4.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion