Intel

AIKIDO-2026-10178

rulesync is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 16, 2026

45

Medium Risk

This Affects:

JSrulesync
0.1.0 - 6.4.0
Fixed in 6.5.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package lack sufficient validation and sanitization when handling file paths, repository inputs, and remote fetch operations, allowing improper path handling, weak hostname validation, and unsafe API parameter usage. An attacker could exploit these weaknesses by supplying crafted repository URLs, malicious output paths, or manipulated file references to trigger path traversal, overwrite arbitrary files, bypass trusted domain checks, or force the system to fetch malicious or oversized files, potentially leading to unauthorized file access, data tampering, or denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

rulesync is vulnerable to Improper Input Validation in versions 0.1.0 - 6.4.0.

How to fix this

Upgrade the rulesync library to the patch version.