CyberRota Analysis
AI-GeneratedTinyWeb versions up to 0.0.8 are vulnerable to a path traversal flaw that enables unauthenticated attackers to access arbitrary files on the server by exploiting the URL path with ../ sequences. This could lead to the exposure of sensitive information, including credential stores and private keys, particularly if the server operates with root privileges. Organizations using TinyWeb should prioritize patching this vulnerability to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without normalization, dot-segment removal, or boundary checks. Attackers can craft a single request with ../ sequences that pass through the URL parser unchanged and reach the filesystem call via HttpFile::setFile(), exposing sensitive files such as credential stores and private keys when the server process runs as root.