CVE-2026-97365 Details
Description
A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can lead to path traversal. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A path traversal vulnerability has been identified in Chonkie Inc Littrs versions 0.6.1 and 0.6.2. The issue arises in the Sandbox::mount function within the file crates/littrs/src/lib.rs. By manipulating the 'relative' argument, it is possible to traverse directories and access files outside of the intended directory structure. This vulnerability can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chonkie-inc/littrs/ | [email protected] | ProductSource CodeVendor |
| https://github.com/chonkie-inc/littrs/security/advisories/GHSA-j65r-rjxh-fgc4 | [email protected] | AdvisoryBroken LinkVendor |
| https://vuldb.com/cve/CVE-2026-97365 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/909328 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/409349 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/409349/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| chonkie-inc littrs | 0.6.1 (semver) 0.6.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion