Executive brief
Wisp, a web framework for the Gleam programming language, contains a flaw in how it handles static file requests. An attacker can use specially crafted web requests to bypass security filters and read sensitive files from the server, such as application source code, configuration files, and system credentials. This could lead to a full compromise of the application's data and secrets.
Technical details
The `wisp.serve_static` function in `src/wisp.gleam` is vulnerable to a path traversal attack (CWE-22) due to an incorrect order of operations. The function attempts to sanitize the request path by removing literal '..' sequences before performing percent-decoding. An attacker can bypass this filter by using percent-encoded sequences like '%2e%2e'. After the filter runs, the application decodes these sequences back into '..', allowing the attacker to traverse outside the intended directory. This can be exploited by an unauthenticated remote attacker via a single HTTP request to read sensitive files like /etc/passwd or application source code. The issue is fixed in version 2.2.1.
Affected products
- gleam-wisp wisp >= 2.1.1, < 2.2.1
Timeline
- 2026-03-09: disclosed
- 2026-03-10: advisory: NVD publication
- 2026-03-11: patched: GitHub Advisory published and reviewed