CVE-2025-68705: 
Rust vulnerability analysis and mitigation

Overview

CVE-2025-68705 is a path traversal vulnerability in RustFS, an open-source distributed object storage system built in Rust. The flaw exists in the /rustfs/rpc/read_file_stream endpoint and allows attackers with knowledge of the RPC secret to read (and potentially write) arbitrary files on the host system. Affected versions span 1.0.0-alpha.13 through 1.0.0-alpha.78; the issue was disclosed and patched on January 7, 2026, with the fix released in version 1.0.0-alpha.79. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 score of 8.8 (High) (Github Advisory, RustFS Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) in crates/ecstore/src/disk/local.rs at line 1791. The vulnerable code uses Rust's PathBuf::join() to construct a file path from user-supplied input without canonicalization, boundary validation, or protection against ../ sequences or absolute paths — only a length check is performed via check_path_length(). An attacker can supply a traversal payload such as ../../../../etc/passwd in the path query parameter, causing the resolved path to escape the intended volume directory entirely. Exploitation requires a valid HMAC-SHA256 RPC signature (computed as HMAC-SHA256(secret, "{url}|{method}|{timestamp}")), the RPC secret key (defaulting to rustfs-default-secret or rustfsadmin), a registered disk ID, and a valid volume name (RustFS Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker to read arbitrary files accessible to the RustFS process, including sensitive system files (/etc/passwd, /etc/hosts), SSH private keys, application secrets, environment variables from /proc, and RustFS configuration files. A similar vulnerability is suspected in the put_file_stream endpoint, which could enable arbitrary file writes — potentially allowing modification of cron jobs, authorized_keys, or system binaries depending on process permissions. The availability impact is rated medium, as the walk_dir endpoint could be abused for filesystem enumeration or denial-of-service via recursive traversal (RustFS Advisory).

Exploitability

Proof-of-concept exploit code is publicly available, including a Python PoC script referenced in the security advisory and a dedicated GitHub repository (imjdl/CVE-2025-68705-RustFS-Path-Traversal-Vulnerability-Check). Exploitation has been reported by multiple sources including vulners.com, and the CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. The EPSS score is approximately 0.092% (26th percentile). The vulnerability is not currently listed in the CISA KEV catalog. Exploitation is trivial when the default RPC secret is in use, but impossible without knowledge of the secret (Github Advisory, RustFS Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing RustFS instances (versions alpha.13–alpha.78) using Shodan, Censys, or similar tools targeting port 9000. Confirm the RustFS RPC endpoint is accessible at /rustfs/rpc/read_file_stream.
  2. Obtain RPC Secret: Attempt to use the default secret (rustfs-default-secret or rustfsadmin). In production environments, the secret may be obtained via leaked environment variables, configuration files, or other means.
  3. Identify Valid Disk and Volume: Enumerate or guess a valid disk ID (e.g., /data/rustfs0) and volume name (e.g., .rustfs.sys) registered in the RustFS instance.
  4. Determine Target File Size: For successful reads, the length parameter must match the exact file size. Use prior knowledge or trial-and-error for common files (e.g., /etc/passwd is typically ~751 bytes).
  5. Compute HMAC-SHA256 Signature: Generate the required RPC signature: Base64(HMAC-SHA256(secret, "{url}|{method}|{timestamp}")) and set the x-rustfs-timestamp header to the current Unix timestamp.
  6. Send Traversal Request: Issue a crafted GET request:
    GET /rustfs/rpc/read_file_stream?disk=/data/rustfs0&volume=.rustfs.sys&path=../../../../etc/passwd&offset=0&length=751
    x-rustfs-signature: <computed_signature>
    x-rustfs-timestamp: <unix_timestamp>
  7. Retrieve Arbitrary Files: On HTTP 200 response, the file contents are returned. Repeat for other sensitive targets such as /root/.ssh/id_rsa, /proc/1/environ, or RustFS config files (RustFS Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /rustfs/rpc/read_file_stream containing ../ sequences or absolute paths (e.g., /etc/passwd, /etc/hosts, /root/.ssh/) in the path query parameter; repeated requests with varying length values suggesting file size enumeration.
  • Logs: RustFS access logs showing requests to the RPC endpoint with traversal patterns in query parameters; HTTP 200 responses to requests with path values containing .. or starting with /; requests from unexpected source IPs to the RPC port (default 9000).
  • File System: Unexpected access timestamps on sensitive system files (/etc/passwd, /etc/shadow, /root/.ssh/id_rsa) coinciding with RustFS process activity.
  • Process: Unusual file read operations by the RustFS process (rustfs, UID 10001) on files outside the configured data directories, observable via auditd or similar file access monitoring tools (RustFS Advisory).

Mitigation and workarounds

Upgrade RustFS to version 1.0.0-alpha.79 or later, which introduces path canonicalization and boundary validation in the read_file_stream handler (commit ab752458) (Patch Commit). If immediate patching is not possible, apply the following mitigations: (1) restrict network access to the /rustfs/rpc/read_file_stream endpoint using firewall rules or network segmentation, limiting it to trusted internal networks only; (2) immediately rotate the RUSTFS_SECRET_KEY away from any default value (rustfs-default-secret, rustfsadmin); (3) run RustFS with least-privilege file system permissions to limit the scope of readable files. Monitor RustFS logs for suspicious path patterns as described in the IOC section (RustFS Advisory).

Community reactions

The vulnerability was discovered and responsibly reported by bilisheep from the Xmirror Security Team, with additional acknowledgment to @realansgar, and was disclosed via GitHub's coordinated disclosure process (RustFS Advisory). The advisory was quickly picked up by vulnerability tracking platforms including vulners.com, VulDB, CVEFeed, and CIRCL's vulnerability lookup service within hours of publication. Check Point also published a defense advisory referencing this CVE (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-6w6g-hm98-mhgmHIGH8.7
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-5j98-2g5x-46v6HIGH7.5
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-cjcg-cxmh-9wcrHIGH7.5
  • Rust logoRust
  • praxis-proxy
NoYesOct 02, 2026
GHSA-6f2x-v7q7-m7m5MEDIUM6.9
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-6g2r-675j-hx59LOW2.3
  • Rust logoRust
  • xxhash-rust
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management