天下漏洞,尽知其名
HIGH

CVE-2026-102811 Marmite 开发服务器认证缺失与路径穿越漏洞

影响未授权攻击者可篡改站点内容并写入任意文件

AI 研判

Marmite 0.4.2 及之前的开发服务器端点 /__marmite__/content、/__marmite__/config 和 /__marmite__/file/ 缺少身份认证,未授权攻击者可直接创建、修改和覆盖站点内容与配置。同时 handle_create_content 和 handle_clone_content 未对路径参数做安全过滤,可结合目录穿越将文件写出项目目录之外。

影响范围

Marmite

Marmite 0.4.2 及更早版本,具体受影响范围以官方公告为准。

漏洞详情

漏洞属于认证缺失与路径穿越的组合问题。开发服务器暴露的多个管理端点未校验请求者身份,任何人可调用内容创建、克隆与配置修改接口。这些接口在处理路径参数时未做规范化与目录限制,攻击者可用 ../ 等序列将文件写入项目目录之外,从而覆盖任意可写文件。

利用条件与风险

利用前提是目标 Marmite 开发服务器可被网络访问,无需认证即可触发;实战中可导致站点被篡改、配置被劫持,并可能通过任意文件写入扩大影响。

修复建议

建议升级至修复该问题的 Marmite 版本,具体版本号暂无公开信息;临时缓解措施为不要将开发服务器暴露在不可信网络,并限制对 /__marmite__/ 路径的访问。

原始情报

Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.