Directory Traversal Vulnerability in Mongoose Embedded Web Server
CVE-2026-73255
6.5MEDIUM
What is CVE-2026-73255?
Mongoose, an embedded web server, contains a vulnerability allowing attackers to exploit server-side includes (SSI) by controlling an SSI-enabled file. This vulnerability enables attackers to embed directory traversal sequences in include directives, potentially disclosing sensitive files that the Mongoose process can read. The issue arises from a failure to validate the filesystem path before processing, which has been mitigated in version 7.22.
Affected Version(s)
mongoose < 7.22
