Rswag Project develops a Rails-based API documentation and testing tool, a narrowly scoped offering with modest vulnerability surface. The observed weakness class centers on path-traversal conditions, reflecting the file-system access patterns inherent to a documentation-generation utility; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rswag Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38337HIGH rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) | Jul 14, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rswag Project.
Media articles that mention a CVE ID that affects a product developed by Rswag Project — matched by CVE ID, not by vendor name.