Junglewise Threat Intelligence

CVE-2026-73255: Cesanta Mongoose directory traversal in SSI processing

CVE-2026-73255 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Vendors: Cesanta.

Executive brief

Mongoose is an embedded web server commonly used in IoT devices and embedded systems. When Server-Side Includes (SSI) are enabled, an attacker who can create or modify SSI-enabled files can use directory traversal sequences to read arbitrary files from the system. This allows disclosure of sensitive files (configuration, credentials, source code) that the Mongoose process can access, potentially exposing confidential data.

Technical details

The vulnerability is a directory traversal flaw in the mg_ssi() function within src/ssi.c. When processing SSI #include directives (both file and virtual variants), the function concatenates user-supplied path arguments directly into filesystem paths without validating them through mg_path_is_sane(). This allows an attacker controlling SSI-enabled files to inject traversal sequences (e.g., ../) to escape the intended directory and read files outside the web root. The attack requires MG_ENABLE_SSI to be compiled in and ssi_pattern to be configured; an attacker needs write access to SSI files or the ability to influence their content. The fix was released in version 7.22.

Affected products

  • Cesanta Mongoose before 7.22

Timeline

  • 2026-06-23: patched: Fix merged in commit a9df523f76f43a38bd53b4232b9cfd4c16869e71
  • 2026-08-20: disclosed

References