{"id":"RUSTSEC-2026-0276","aliases":["GHSA-72g6-wgrg-vhm7","RUSTSEC-2026-0277"],"title":"Path traversal in apimock's file-serving fallback","summary":"Path traversal in apimock's file-serving fallback","severity":"none","vendor":"apimock","product":"apimock","ecosystem":"rust","affected":["apimock >= 5.0.0, < 5.0.0"],"patched":["apimock 5.0.0"],"published":"2026-08-26","updated":"2026-09-02","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0276","references":[{"url":"https://crates.io/crates/apimock"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0276.html"},{"url":"https://github.com/apimokka/apimock-rs/commit/a9c05fec2d36a750c30e797291a0557f230c8faf"}],"tags":["osv","rust"],"ingestedAt":"2026-09-02T19:31:28.144Z","slug":"RUSTSEC-2026-0276","body":"## Overview\n\nThe file-serving fallback joined a request-derived path onto the\nconfigured response directory and checked only that the result existed,\nnever that it stayed inside that directory. A request containing a raw\n`..` segment could read any file readable by the process, returned with\nHTTP 200.\n\nRead-only: no write, no code execution.\n\nOn the 4.x line `apimock` is a single crate containing the serving code.\nFixed in 4.8.1 by canonicalising each resolved path and rejecting\nanything outside its base directory.\n\n**apimock 5.0.0 and later are not affected by this advisory.** From\n5.0.0 the serving code moved to the `apimock-server` crate, which\n`apimock` depends on; that crate carries its own advisory for the same\nissue, fixed in 5.19.1.\n\n## Affected packages\n\n- `apimock >= 5.0.0, < 5.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `apimock 5.0.0`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}