Junglewise Threat Intelligence

CVE-2026-10303: ServerCo getssl path traversal and command injection in ACME challenge

CVE-2026-10303 · Severity: high · CVSS 7.4 · Published 2026-06-16

Executive brief

getssl is a tool used to automate the process of obtaining and renewing security certificates for websites. A security flaw in this tool allows a malicious or compromised certificate provider to send a specially crafted response that can trick the tool into writing files to unauthorized locations on the server. This could allow an attacker to take control of the server, potentially leading to data theft or service disruption.

Technical details

ServerCo getssl version 2.49 and prior contains a path traversal vulnerability (CWE-73) due to insufficient validation of ACME challenge tokens against RFC 8555 specifications. An attacker capable of supplying ACME challenge responses—such as a compromised Certificate Authority (CA) or an adversary performing a man-in-the-middle attack—can provide a token containing directory traversal sequences or shell metacharacters. Because the script uses these tokens in file-handling operations without sanitization, an attacker can achieve unauthorized file writes or remote command injection, often with the elevated privileges under which the script is executed. This issue is addressed in version 2.50.

Affected products

  • ServerCo getssl 2.49 and prior

Timeline

  • 2026-05-30: disclosed: Initial disclosure and pull request submitted
  • 2026-06-04: patched: Version 2.50 released
  • 2026-06-16: advisory: CVE-2026-10303 published

References