Arbitrary File Read Vulnerability in Bruno by UseBruno
CVE-2026-85665

7.1HIGH

Key Information:

Vendor

Usebruno

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85665?

Bruno versions up to 3.4.2 are susceptible to an arbitrary file read vulnerability due to insufficient validation of file paths in request body declarations. This allows attackers to exploit parent-directory traversal segments in crafted requests. When executed, such requests can manipulate the file path to access sensitive files outside the designated collection directory. Consequently, this flaw permits the unauthorized reading and potential exfiltration of arbitrary local files to attacker-controlled servers.

Affected Version(s)

bruno 0 <= 4.1.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.