Junglewise Threat Intelligence

CVE-2026-85665: Bruno path traversal in request body file declarations

CVE-2026-85665 · Severity: medium · CVSS 6.5 · Published 2026-09-04

Executive brief

Bruno is a lightweight open-source API testing tool used by developers to build and test APIs, similar to Postman. Versions through 4.1.0 fail to properly validate file paths in request bodies, allowing attackers to read any file on a developer's system by crafting requests with directory traversal sequences (../) and sending the contents to attacker-controlled servers.

Technical details

This is a path traversal vulnerability (CWE-22) in Bruno's request preparation module. The vulnerability exists because file paths specified in request body declarations are not validated to ensure they remain within the collection directory. An attacker can craft a malicious collection containing requests with body:file paths containing ../ sequences that resolve outside the intended boundary. When the collection is executed, Bruno reads the specified files and exfiltrates their contents to attacker-controlled endpoints. The vulnerability requires local collection access and collection execution to be exploited.

Affected products

  • Bruno Bruno through 4.1.0

Timeline

  • 2026-09-04: disclosed

References