RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0277

Path traversal in apimock-server's file-serving fallback

Reported
Issued
Package
apimock-server (crates.io)
Type
Vulnerability
Categories
Keywords
#path-traversal #http #file-serving
Aliases
References
CVSS Score
8.2 HIGH
CVSS Details
Attack Complexity
Low
Attack Requirements
Present
Attack Vector
Network
Privileges Required
None
Availability Impact to the Subsequent System
None
Confidentiality Impact to the Subsequent System
None
Integrity Impact to the Subsequent System
None
User Interaction
None
Availability Impact to the Vulnerable System
None
Confidentiality Impact to the Vulnerable System
High
Integrity Impact to the Vulnerable System
None
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Patched
  • >=5.19.1

Description

The file-serving fallback joined a request-derived path onto the configured response directory and checked only that the result existed, never that it stayed inside that directory. A request containing a raw .. segment could read any file readable by the process, returned with HTTP 200.

Read-only: no write, no code execution.

Exposure depends on the bind address. The default is 127.0.0.1; deployments binding 0.0.0.0 or a LAN address are reachable from the network. Most HTTP clients normalise .. away before sending, so reaching it requires a client that does not.

All published versions before 5.19.1 are affected. Fixed in 5.19.1 by canonicalising each resolved path and rejecting anything outside its base directory.

This advisory also covers apimock 5.x, which depends on apimock-server. apimock 4.x predates the crate split and carries its own advisory for the same issue, fixed in 4.8.1.

Advisory available under CC0-1.0 license.