
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68705 is a path traversal vulnerability in RustFS, an open-source distributed object storage system built in Rust. The flaw exists in the /rustfs/rpc/read_file_stream endpoint and allows attackers with knowledge of the RPC secret to read (and potentially write) arbitrary files on the host system. Affected versions span 1.0.0-alpha.13 through 1.0.0-alpha.78; the issue was disclosed and patched on January 7, 2026, with the fix released in version 1.0.0-alpha.79. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 score of 8.8 (High) (Github Advisory, RustFS Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) in crates/ecstore/src/disk/local.rs at line 1791. The vulnerable code uses Rust's PathBuf::join() to construct a file path from user-supplied input without canonicalization, boundary validation, or protection against ../ sequences or absolute paths — only a length check is performed via check_path_length(). An attacker can supply a traversal payload such as ../../../../etc/passwd in the path query parameter, causing the resolved path to escape the intended volume directory entirely. Exploitation requires a valid HMAC-SHA256 RPC signature (computed as HMAC-SHA256(secret, "{url}|{method}|{timestamp}")), the RPC secret key (defaulting to rustfs-default-secret or rustfsadmin), a registered disk ID, and a valid volume name (RustFS Advisory, Github Advisory).
Successful exploitation allows an attacker to read arbitrary files accessible to the RustFS process, including sensitive system files (/etc/passwd, /etc/hosts), SSH private keys, application secrets, environment variables from /proc, and RustFS configuration files. A similar vulnerability is suspected in the put_file_stream endpoint, which could enable arbitrary file writes — potentially allowing modification of cron jobs, authorized_keys, or system binaries depending on process permissions. The availability impact is rated medium, as the walk_dir endpoint could be abused for filesystem enumeration or denial-of-service via recursive traversal (RustFS Advisory).
Proof-of-concept exploit code is publicly available, including a Python PoC script referenced in the security advisory and a dedicated GitHub repository (imjdl/CVE-2025-68705-RustFS-Path-Traversal-Vulnerability-Check). Exploitation has been reported by multiple sources including vulners.com, and the CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. The EPSS score is approximately 0.092% (26th percentile). The vulnerability is not currently listed in the CISA KEV catalog. Exploitation is trivial when the default RPC secret is in use, but impossible without knowledge of the secret (Github Advisory, RustFS Advisory).
/rustfs/rpc/read_file_stream.rustfs-default-secret or rustfsadmin). In production environments, the secret may be obtained via leaked environment variables, configuration files, or other means./data/rustfs0) and volume name (e.g., .rustfs.sys) registered in the RustFS instance.length parameter must match the exact file size. Use prior knowledge or trial-and-error for common files (e.g., /etc/passwd is typically ~751 bytes).Base64(HMAC-SHA256(secret, "{url}|{method}|{timestamp}")) and set the x-rustfs-timestamp header to the current Unix timestamp.GET /rustfs/rpc/read_file_stream?disk=/data/rustfs0&volume=.rustfs.sys&path=../../../../etc/passwd&offset=0&length=751
x-rustfs-signature: <computed_signature>
x-rustfs-timestamp: <unix_timestamp>/root/.ssh/id_rsa, /proc/1/environ, or RustFS config files (RustFS Advisory, Github Advisory)./rustfs/rpc/read_file_stream containing ../ sequences or absolute paths (e.g., /etc/passwd, /etc/hosts, /root/.ssh/) in the path query parameter; repeated requests with varying length values suggesting file size enumeration.path values containing .. or starting with /; requests from unexpected source IPs to the RPC port (default 9000)./etc/passwd, /etc/shadow, /root/.ssh/id_rsa) coinciding with RustFS process activity.rustfs, UID 10001) on files outside the configured data directories, observable via auditd or similar file access monitoring tools (RustFS Advisory).Upgrade RustFS to version 1.0.0-alpha.79 or later, which introduces path canonicalization and boundary validation in the read_file_stream handler (commit ab752458) (Patch Commit). If immediate patching is not possible, apply the following mitigations: (1) restrict network access to the /rustfs/rpc/read_file_stream endpoint using firewall rules or network segmentation, limiting it to trusted internal networks only; (2) immediately rotate the RUSTFS_SECRET_KEY away from any default value (rustfs-default-secret, rustfsadmin); (3) run RustFS with least-privilege file system permissions to limit the scope of readable files. Monitor RustFS logs for suspicious path patterns as described in the IOC section (RustFS Advisory).
The vulnerability was discovered and responsibly reported by bilisheep from the Xmirror Security Team, with additional acknowledgment to @realansgar, and was disclosed via GitHub's coordinated disclosure process (RustFS Advisory). The advisory was quickly picked up by vulnerability tracking platforms including vulners.com, VulDB, CVEFeed, and CIRCL's vulnerability lookup service within hours of publication. Check Point also published a defense advisory referencing this CVE (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."