THREAT OPS › Threat News › [NVD] CVE-2026-85665 (MEDIUM 6.5) — Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../
[NVD] CVE-2026-85665 (MEDIUM 6.5) — Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../
CVE-2026-85665 CVSS: 6.5 MEDIUM Published: 2026-09-04T15:17:44.247
Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection direct
Indicators of compromise
- CVE-2026-85665cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85665