high · CVSS v3 8.1 · CVSS v4 8.6
CVE-2026-103398
OpenSave 2.4.0 allows path traversal via manifest requests, enabling attackers to read and write arbitrary files outside configured director
Overview
OpenSave 2.4.0 allows path traversal via manifest requests, enabling attackers to read and write arbitrary files outside configured directories. This flaw can be exploited by any peer connected to the sync service. It undermines data integrity and confidentiality.
Description
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.
Impact
Confidentiality: attackers can read arbitrary files. Integrity: attackers can modify or delete files. Availability: potential disruption of sync service. Defenders: administrators of OpenSave deployments and network security teams.
Remediation
Apply the vendor patch that enforces strict path validation for manifest requests. If a patch is unavailable, restrict peer access via firewall or VPN and enforce a directory whitelist on the server. Monitor logs for unexpected file operations.
Risk context
Severity high, CVSS 8.1/8.6. No EPSS data. Defenders should treat this as a high-priority vulnerability requiring prompt patching.
Affected products
- OpenSave 2.4.0
- OpenSave
Scores
- Severity
- high
- CVSS v2
- 8.5
- CVSS v3
- 8.1
- CVSS v4
- 8.6
- EPSS
- —