RUSTSEC-2026-0276
Path traversal in apimock's file-serving fallback
Details
The file-serving fallback joined a request-derived path onto the configured response directory and checked only that the result existed, never that it stayed inside that directory. A request containing a raw `..` segment could read any file readable by the process, returned with HTTP 200.
Read-only: no write, no code execution.
On the 4.x line `apimock` is a single crate containing the serving code. Fixed in 4.8.1 by canonicalising each resolved path and rejecting anything outside its base directory.
**apimock 5.0.0 and later are not affected by this advisory.** From 5.0.0 the serving code moved to the `apimock-server` crate, which `apimock` depends on; that crate carries its own advisory for the same issue, fixed in 5.19.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 4.8.1Upgrade apimock to 4.8.1 or newer (ecosystem crates.io).