Executive brief
Gerapy, a distributed crawler management framework, contains a security vulnerability in its project upload feature. An unauthenticated remote attacker can upload malicious files to the server, potentially leading to unauthorized code execution and full system compromise. This flaw bypasses intended security controls, allowing anyone with network access to the management interface to interfere with operations or access sensitive data.
Technical details
A vulnerability in Gerapy up to 0.9.13 involves missing authentication and improper path validation in the 'project_upload' endpoint within 'gerapy/server/core/views.py'. The '@permission_classes([IsAuthenticated])' decorator was commented out, allowing unauthenticated network access to the function. Furthermore, the endpoint used 'zip_ref.extractall()' on uploaded archives without validating entry names, enabling a 'Zip Slip' path traversal attack. A remote attacker can exploit these combined issues to upload a crafted ZIP file containing directory traversal sequences (e.g., ../../../), writing arbitrary files to the filesystem to achieve Remote Code Execution (RCE). A patch (commit bd4891c) has been released to re-enable authentication and implement path validation.
Affected products
- Gerapy Gerapy up to 0.9.13
Timeline
- 2026-07-04: patched: Fix merged in GitHub pull request 319
- 2026-07-19: advisory: NVD publication date