Routinator has cache path traversal when processing the module component of rsync URIs
High severity
GitHub Reviewed
Published
Jun 8, 2026
to the GitHub Advisory Database
•
Updated Jun 12, 2026
Description
Published by the National Vulnerability Database
Jun 8, 2026
Published to the GitHub Advisory Database
Jun 8, 2026
Reviewed
Jun 12, 2026
Last updated
Jun 12, 2026
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
References