cesanta.mongoose is vulnerable to Path Traversal
65
Medium Risk
When Server-Side Includes are enabled, the include directive handler concatenates the directive path into a filesystem path without sanitizing ../ sequences. Content that reaches an .shtml file can therefore read arbitrary files readable by the process, such as system password files, configuration, or private keys. Exploitation requires control over included content but no elevated privileges. The fix validates include paths before opening them.
You are affected if you are using a version that falls within the vulnerable range and you enable Server-Side Includes (MG_ENABLE_SSI) and serve .shtml content that untrusted input can influence.
cesanta.mongoose is vulnerable to Path Traversal in versions 7.1.0 - 7.21.0.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant