Executive brief
rustypaste is a minimal file upload and pastebin service. A path traversal vulnerability allows attackers to bypass directory restrictions and write files to arbitrary locations on the system by including traversal sequences in the custom filename HTTP header, potentially leading to system compromise or data exposure.
Technical details
rustypaste validates the upload destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. The vulnerability class is path traversal (CWE-22). An unauthenticated attacker can send an HTTP request with path traversal sequences (e.g., "../../../") in the filename header to write files outside the configured upload directory to arbitrary filesystem locations. The attack requires network reachability to the upload endpoint but no authentication. A patch is available in version 0.18.1.
Affected products
- orhun rustypaste before 0.18.1
Timeline
- 2026-09-13: disclosed: CVE-2026-90774 published on NVD
- 0.18.1: patched: Fix available in version 0.18.1