CVE-2026-67185: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GeneralSandman TinyWeb
TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without normalization, dot-segment removal, or boundary checks. Attackers can craft a single request with ../ sequences that pass through the URL parser unchanged and reach the filesystem call via HttpFile::setFile(), exposing sensitive files such as credential stores and private keys when the server process runs as root.
AI Analysis
Technical Summary
CVE-2026-67185 is a path traversal vulnerability in GeneralSandman TinyWeb up to version 0.0.8. The issue arises in the HttpBuilder::buildResponse() function, where URL paths containing '../' sequences are concatenated directly to the configured web root without normalization, dot-segment removal, or boundary validation. This allows attackers to craft requests that bypass URL parsing and reach filesystem calls in HttpFile::setFile(), enabling unauthorized reading of arbitrary files. The vulnerability is exploitable without authentication and can lead to exposure of sensitive files if the server process has elevated privileges.
Potential Impact
An attacker can read arbitrary files on the server hosting TinyWeb 0.0.8 without authentication. This can lead to disclosure of sensitive information such as credential stores and private keys, particularly if the server runs as root. The vulnerability poses a high risk to confidentiality but does not indicate impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict access to the TinyWeb server, avoid running the server with root privileges, and monitor for suspicious requests containing path traversal patterns. Do not rely on this as a permanent solution; apply vendor patches once released.
CVE-2026-67185: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GeneralSandman TinyWeb
Description
TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without normalization, dot-segment removal, or boundary checks. Attackers can craft a single request with ../ sequences that pass through the URL parser unchanged and reach the filesystem call via HttpFile::setFile(), exposing sensitive files such as credential stores and private keys when the server process runs as root.
CVSS v4.0
Score 8.7high
Affected software
GeneralSandman
TinyWeb
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67185 is a path traversal vulnerability in GeneralSandman TinyWeb up to version 0.0.8. The issue arises in the HttpBuilder::buildResponse() function, where URL paths containing '../' sequences are concatenated directly to the configured web root without normalization, dot-segment removal, or boundary validation. This allows attackers to craft requests that bypass URL parsing and reach filesystem calls in HttpFile::setFile(), enabling unauthorized reading of arbitrary files. The vulnerability is exploitable without authentication and can lead to exposure of sensitive files if the server process has elevated privileges.
Potential Impact
An attacker can read arbitrary files on the server hosting TinyWeb 0.0.8 without authentication. This can lead to disclosure of sensitive information such as credential stores and private keys, particularly if the server runs as root. The vulnerability poses a high risk to confidentiality but does not indicate impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict access to the TinyWeb server, avoid running the server with root privileges, and monitor for suspicious requests containing path traversal patterns. Do not rely on this as a permanent solution; apply vendor patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-28T16:06:49.773Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a68de689c2644c7f8e9c238
Added to database: 07/28/2026, 16:52:56 UTC
Last enriched: 07/29/2026, 16:07:55 UTC
Last updated: 09/10/2026, 20:01:13 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.