Executive brief
webui-aria2 is a web interface for the aria2 download manager. An attacker can read any file on the server that the application has access to by crafting specially-formed requests with path traversal sequences (e.g., `../../../etc/passwd`), exposing sensitive configuration files, credentials, and other data.
Technical details
The vulnerability is a classic path traversal (CWE-22) in the Node.js server component (`node-server.js`), where user-supplied filenames from URL requests are not sanitized before being used in file operations. An unauthenticated attacker can leverage this by sending HTTP requests with path traversal sequences (../, ..\.., etc.) to escape the intended serving directory and access arbitrary files readable by the web server process. The attack requires network access to the exposed service and no authentication. An attacker can read sensitive files including configuration, source code, and system files.
Affected products
- webui-aria2 webui-aria2 1.0.1 and earlier
Timeline
- 2023-08-22: disclosed
- 2023-08-14: other: PoC published on GitHub Gist