Vulnerability DatabaseRUSTSEC-2021-0126

RUSTSEC-2021-0126
Rust vulnerability analysis and mitigation

Overview

A directory traversal vulnerability was discovered in the rust-embed crate versions prior to 6.3.0. The vulnerability, tracked as RUSTSEC-2021-0126 and CVE-2021-45712, was identified on December 26, 2021. The issue specifically affects applications using rust-embed in debug mode, where path traversal attacks could be possible (RustSec Advisory).

Technical details

The vulnerability allows for directory traversal attacks through the use of '../' path sequences when the application is running in debug mode. This could potentially allow attackers to access files outside of the intended directory structure. A proof of concept demonstrates that by using the appropriate number of '../' sequences, an attacker could access sensitive system files such as '/etc/passwd' (GitHub Issue).

Impact

When exploited, this vulnerability could allow unauthorized access to files outside of the intended directory structure, potentially exposing sensitive system files and information. The impact is particularly concerning in debug mode deployments where an attacker could traverse the directory structure to read arbitrary files on the system (RustSec Advisory).

Mitigation and workarounds

The vulnerability has been fixed in rust-embed version 6.3.0 and later. Users are strongly advised to upgrade to the latest version to address this security issue. For those unable to upgrade immediately, it is recommended to ensure that applications using rust-embed are not deployed in debug mode (RustSec Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66627HIGH8.4
  • RustRust
  • wasmi
NoYesDec 09, 2025
GHSA-xrv8-2pf5-f3q7MEDIUM6
  • RustRust
  • nitro-tpm-pcr-compute
NoYesDec 05, 2025
CVE-2025-67487MEDIUM5.5
  • RustRust
  • static-web-server
NoYesDec 09, 2025
CVE-2025-66622LOW1.3
  • RustRust
  • matrix-sdk-base
NoYesDec 09, 2025
RUSTSEC-2025-0135N/AN/A
  • RustRust
  • matrix-sdk-base
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management