CVE-2026-102811 Details
Description
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.
A vulnerability exists in Marmite static site generator, specifically in versions through 0.4.2, due to missing authentication in the development server endpoints. This flaw allows unauthenticated attackers to access the content management API, including endpoints for managing site content, configuration, and files. The vulnerability arises from unsanitized path parameters that can be exploited to perform directory traversal, writing files outside the intended project directory. This issue was reported by a user named Ikram-4.
Users can update to Marmite version 0.4.3, which addresses the authentication vulnerability by defaulting the server bind address to '127.0.0.1:8000' and clearly identifying the server as development-only. However, this version does not fix the broader path traversal issue, so users should be cautious when using the development server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rochacbruno marmite | <= 0.4.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
| Sep 29, 2026 | CVE Modified | CISA-ADP |
Volerion