VDB
Sign up
HIGH7.5

GHSA-9jg3-g3wh-w9pj

Yamcs has Unauthenticated Directory Traversal

Quick fix

GHSA-9jg3-g3wh-w9pj — org.yamcs:yamcs-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.12.0</version> for org.yamcs:yamcs-core

Details

### Attack type:  Unauthenticated remote 

### Impact: Attackers can access any system files from the underlying host.

### Affected components: HttpRequestHandler.java, StaticFileHandler.java

An Unauthenticated Directory Traversal vulnerability exists in Yamcs <=5.8.6, allowing anyone to access any file on the underlying operating system. This allows unauthenticated attackers to download sensitive files and data.

<img width="2170" height="1289" alt="image" src="https://github.com/user-attachments/assets/8d426da1-5351-4240-a290-8d858be61312" />

## Steps to Reproduce: 1. Start Yamcs and login as a user 2. Paste the following URL in the browser and press enter:

``` http://localhost:8090//etc/passwd ```

3. The `/etc/passwd` file will be downloaded.

## Acknowledgements This vulnerability was discovered by Abderrahim Dahmani while solving a STARPWN 2025 CTF challenge at DEFCON 33 offered by VisionSpace Technologies.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.yamcs:yamcs-core
Introduced in: 0Fixed in: 5.12.0
Fix# pom.xml: bump <version>5.12.0</version> for org.yamcs:yamcs-core

References