VYPR
High severity7.5NVD Advisory· Published Jun 8, 2026· Updated Jun 12, 2026

CVE-2026-49233

CVE-2026-49233

Description

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
routinatorcrates.io
< 0.15.20.15.2

Affected products

3
  • Nlnetlabs/Routinatorinferred3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:*range: <0.15.2
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

1