OVERVIEW CVE-2026-34783 is a path traversal vulnerability in Ferret, a declarative web data processing system, affecting versions prior to 2.0.0-alpha.4. The vulnerability exists in the IO::FS::WRITE standard library function and allows attackers to write arbitrary files to the filesystem when an operator scrapes websites that return filenames containing directory traversal sequences (../). SEVERITY This vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) with a network-based attack vector requiring no authentication but necessitating user interaction. The attack has low complexity and poses high integrity and availability impacts. The primary risk stems from the ability to place malicious code in sensitive locations such as cron jobs, SSH authorized_keys files, shell profiles, or web shells, potentially enabling remote code execution with the privileges of the Ferret process. EXPLOITATION STATUS The vulnerability is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog and shows no indication of active exploitation in the wild. The EPSS score of 0.00136 places this vulnerability in the lower percentile of exploitability across all CVEs, suggesting limited practical exploitation likelihood. Community attention appears minimal, and the vulnerability status remains inactive on vulnerability tracking hot lists. The fix has been available since the release of version 2.0.0-alpha.4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:montferret:ferret:*:*:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:montferret:ferret:2.0.0:alpha1:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:montferret:ferret:2.0.0:alpha2:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:montferret:ferret:2.0.0:alpha3:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.