Executive brief
Saltcorn is a no-code application builder whose mobile sync feature allows offline data synchronization. Two unauthenticated endpoints lack proper path validation, enabling an attacker to create files and directories anywhere on the server and read sensitive data from any accessible directory. This could lead to system compromise, data exposure, or service disruption by writing to critical system locations or configuration files.
Technical details
Two unauthenticated path traversal vulnerabilities exist in sync.js due to missing input validation. Finding 1 (line 226): The POST /sync/offline_changes endpoint uses the newSyncTimestamp parameter directly in path.join() without sanitization, allowing an attacker to supply "../" sequences to escape the intended sync directory and write a changes.json file with attacker-controlled JSON content anywhere on the filesystem. Finding 2 (line 288): The GET /sync/upload_finished endpoint similarly uses the dir_name query parameter without validation, permitting directory listing and reading of specific JSON files from arbitrary filesystem locations. Both endpoints lack authentication middleware. The codebase contains File.normalise_in_base() function (used correctly in the clean_sync_dir endpoint at line 342) that prevents path traversal, but was not applied to these two endpoints. No authentication is required and the attack is trivially exploitable via HTTP requests. An attacker can achieve arbitrary file write (potential RCE via cron/systemd/Node.js paths) and arbitrary information disclosure.
Affected products
- Saltcorn @saltcorn/server <1.4.5, 1.5.0-beta.0 to <1.5.5, 1.6.0-alpha.0 to <1.6.0-beta.4
Timeline
- 2026-04-10: disclosed: Vulnerability published on GitHub and OSV
- 2026-04-10: patched: Patches available: 1.4.5, 1.5.5, 1.6.0-beta.4