Arbitrary File Read Vulnerability in Bruno by UseBruno
CVE-2026-85665
7.1HIGH
What is CVE-2026-85665?
Bruno versions up to 3.4.2 are susceptible to an arbitrary file read vulnerability due to insufficient validation of file paths in request body declarations. This allows attackers to exploit parent-directory traversal segments in crafted requests. When executed, such requests can manipulate the file path to access sensitive files outside the designated collection directory. Consequently, this flaw permits the unauthorized reading and potential exfiltration of arbitrary local files to attacker-controlled servers.
Affected Version(s)
bruno 0 <= 4.1.0
