Path Traversal Vulnerability in Facil.io by Boaz Segev
CVE-2026-16653
Key Information:
Badges
What is CVE-2026-16653?
A significant security flaw has been identified in the facil.io framework, specifically within the http_sendfile2 function located in the file lib/facil/http/http.c, which serves as a Public Folder Handler. This vulnerability allows for path traversal attacks, enabling unauthorized access to restricted directories and potentially sensitive files within the system. Attackers can exploit this flaw remotely, as the exploit has already been made public. Although the development team was made aware of this issue through an early report, no fix has been issued as of yet, posing ongoing risks to users of facil.io versions up to 0.7.58.
Affected Version(s)
facil.io 0.7.0
facil.io 0.7.1
facil.io 0.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
