CVE-2026-71268 PUBLISHED

OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write

Assigner: TuranSec
Reserved: 05.08.2026 Published: 05.08.2026 Updated: 05.08.2026

OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses (*FILE:path content*) directives from uploaded Structured Text (.st) program files and writes the referenced content to os.path.join('./core', file_path) with no validation that file_path stays within the ./core directory. A crafted .st file containing a directive such as (*FILE:../../../etc/cron.d/x * * * * root <command>*) writes attacker-controlled content to an arbitrary filesystem path, enabling remote code execution (e.g. via cron or SSH authorized_keys). A path-validation function, validate_file_path(), exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program(), leaving the sink unprotected. OpenPLC additionally ships with hardcoded default credentials (openplc:openplc), lowering the practical bar for exploitation.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor thiagoralves
Product OpenPLC_v3
Versions Default: unaffected
  • affected from 0 to * (incl.)

Credits

  • Alibek Baxtiyorov finder

References

Problem Types

  • CWE-22 CWE