High severity7.7NVD Advisory· Published Jan 20, 2021· Updated Jun 17, 2026
CVE-2021-21269
CVE-2021-21269
Description
Keymaker is a Mastodon Community Finder based Matrix Community serverlist page Server. In Keymaker before version 0.2.0, the assets endpoint did not check for the extension. The rust join method without checking user input might have made it abe to do a Path Traversal attack causing to read more files than allowed. This is fixed in version 0.2.0.
Affected products
2<0.2.0+ 1 more
- (no CPE)range: <0.2.0
- (no CPE)range: < 0.2.0
Patches
Vulnerability mechanics
References
2- github.com/keymaker-mx/keymaker/commit/63f3012b390ff1519a84100df9e5dff5058bb926nvdPatchThird Party Advisory
- github.com/keymaker-mx/keymaker/security/advisories/GHSA-pg25-xfcf-vjvmnvdThird Party Advisory
News mentions
0No linked articles in our index yet.