GHSA-j4pw-7rqh-x2mjHighCVSS 7.5

Marmite through 0.4.2 contains missing authentication in the development server endpoints ...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Marmite through 0.4.2 contains missing authentication in the development server endpoints /marmite/content, /marmite/config, and /marmite/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.

🔗 References (9)