CVE-2026-103398 PUBLISHED

OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 30.09.2026 Updated: 30.09.2026

OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Liquid-co
Product OpenSave
Versions Default: unaffected
  • affected from 0 to 2.4.0 (incl.)

Credits

  • mansurmavlankulov finder

References

Problem Types

  • External Control of File Name or Path CWE