CVE 8.6 HIGH

Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket_CVE-2026-53777

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact_name or download_path fields, causing the client to overwrite sensitive files or expose arbitrary local files to an attacker-accessible location.

AI Analysis

Path traversal vulnerability in Perry before 0.5.1159 via unsanitized path components in ArtifactReady WebSocket messages

Basic Information

ID CVE-2026-53777
Source VulnCheck
Published Jun 11, 2026 at 14:47
Modified Jun 11, 2026 at 16:12

Affected Product

Vendor PerryTS
Product perry
Affected Versions PerryTS perry 0

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor PerryTS
Product Perry
Version 0.5.1159

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.