OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write
Description
OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses (*FILE:path content*) directives from uploaded Structured Text (.st) program files and writes the referenced content to os.path.join('./core', file_path) with no validation that file_path stays within the ./core directory. A crafted .st file containing a directive such as (*FILE:../../../etc/cron.d/x * * * * root *) writes attacker-controlled content to an arbitrary filesystem path, enabling remote code execution (e.g. via cron or SSH authorized_keys). A path-validation function, validate_file_path(), exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program(), leaving the sink unprotected. OpenPLC additionally ships with hardcoded default credentials (openplc:openplc), lowering the practical bar for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: v3
- Range: v3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.