THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-85665 (MEDIUM 6.5) — Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../

[NVD] CVE-2026-85665 (MEDIUM 6.5) — Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../

mednvdPublished 2026-09-04

CVE-2026-85665 CVSS: 6.5 MEDIUM Published: 2026-09-04T15:17:44.247

Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection direct

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85665