CVE-2026-102811
7.5 HIGHpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-306
Public exploit & PoC references
- https://github.com/rochacbruno/marmite
- https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/content.rs#L1064-L1075
- https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/content.rs#L1300-L1322
- https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/server.rs#L455-L475
- https://github.com/rochacbruno/marmite/commit/303a0bf2fff4302f4164c0c39932fdffc6683ad4
- https://github.com/rochacbruno/marmite/issues/554
All references
- https://github.com/rochacbruno/marmite
- https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/content.rs#L1064-L1075
- https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/content.rs#L1300-L1322
- https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/server.rs#L455-L475
- https://github.com/rochacbruno/marmite/commit/303a0bf2fff4302f4164c0c39932fdffc6683ad4
- https://github.com/rochacbruno/marmite/issues/554
- https://www.vulncheck.com/advisories/marmite-through-0.4.2-unauthenticated-api-access-via-development-server
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100192PoC
- HIGHCVE-2026-100672PoC
- HIGHCVE-2026-100746PoC
- MEDIUMCVE-2026-100876PoC
- MEDIUMCVE-2026-100903PoC
- MEDIUMCVE-2026-101004
- CRITICALCVE-2026-101065PoC
- CRITICALCVE-2026-101077PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.