CVE-2026-53777
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
11/06/2026
Última modificación:
11/06/2026
Descripción
*** Pendiente de traducción *** Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact_name or download_path fields, causing the client to overwrite sensitive files or expose arbitrary local files to an attacker-accessible location.
Impacto
Puntuación base 4.0
8.60
Gravedad 4.0
ALTA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/PerryTS/perry/commit/95e1043df8081f67038bffce847dd9ddb3dae046
- https://github.com/PerryTS/perry/pull/4989
- https://github.com/PerryTS/perry/releases/tag/v0.5.1159
- https://github.com/PerryTS/perry/security/advisories/GHSA-x55v-q459-68ch
- https://www.vulncheck.com/advisories/perry-path-traversal-via-artifactready-websocket
- https://github.com/PerryTS/perry/security/advisories/GHSA-x55v-q459-68ch



