Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34783

27
FAUCET Score

OVERVIEW CVE-2026-34783 is a path traversal vulnerability in Ferret, a declarative web data processing system, affecting versions prior to 2.0.0-alpha.4. The vulnerability exists in the IO::FS::WRITE standard library function and allows attackers to write arbitrary files to the filesystem when an operator scrapes websites that return filenames containing directory traversal sequences (../). SEVERITY This vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) with a network-based attack vector requiring no authentication but necessitating user interaction. The attack has low complexity and poses high integrity and availability impacts. The primary risk stems from the ability to place malicious code in sensitive locations such as cron jobs, SSH authorized_keys files, shell profiles, or web shells, potentially enabling remote code execution with the privileges of the Ferret process. EXPLOITATION STATUS The vulnerability is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog and shows no indication of active exploitation in the wild. The EPSS score of 0.00136 places this vulnerability in the lower percentile of exploitability across all CVEs, suggesting limited practical exploitation likelihood. Community attention appears minimal, and the vulnerability status remains inactive on vulnerability tracking hot lists. The fix has been available since the release of version 2.0.0-alpha.4.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0.0CPE matchmatch criteria
cpe:2.3:a:montferret:ferret:*:*:*:*:*:go:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:montferret:ferret:2.0.0:alpha1:*:*:*:go:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:montferret:ferret:2.0.0:alpha2:*:*:*:go:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:montferret:ferret:2.0.0:alpha3:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 42nd percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/MontFerret/ferret/v2Fixed in: 2.0.0-alpha.4

Vendor Advisories (1)

goGHSA-j6v5-g24h-vg4jhigh

Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites

Apr 1, 2026

References

github.com / MontFerret/ferret/commit/160ebad6bd50f153453e120f6d909f5b83322917
Patch
github.com / MontFerret/ferret/security/advisories/GHSA-j6v5-g24h-vg4j
ExploitMitigationVendor Advisory