rootpwn

high · CVSS v3 8.1 · CVSS v4 8.6

CVE-2026-103398

OpenSave 2.4.0 allows path traversal via manifest requests, enabling attackers to read and write arbitrary files outside configured director

Overview

OpenSave 2.4.0 allows path traversal via manifest requests, enabling attackers to read and write arbitrary files outside configured directories. This flaw can be exploited by any peer connected to the sync service. It undermines data integrity and confidentiality.

Description

OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.

Impact

Confidentiality: attackers can read arbitrary files. Integrity: attackers can modify or delete files. Availability: potential disruption of sync service. Defenders: administrators of OpenSave deployments and network security teams.

Remediation

Apply the vendor patch that enforces strict path validation for manifest requests. If a patch is unavailable, restrict peer access via firewall or VPN and enforce a directory whitelist on the server. Monitor logs for unexpected file operations.

Risk context

Severity high, CVSS 8.1/8.6. No EPSS data. Defenders should treat this as a high-priority vulnerability requiring prompt patching.

Affected products

  • OpenSave 2.4.0
  • OpenSave

Scores

Severity
high
CVSS v2
8.5
CVSS v3
8.1
CVSS v4
8.6
EPSS
—

path-traversal file-write OpenSave high-severity manifest sync confidentiality

← All CVEs