---
id: CVE-2026-103398
title: >-
  OpenSave through 2.4.0 fails to properly validate save paths supplied by
  paired peers in the manifest request handler
summary: >-
  OpenSave through 2.4.0 fails to properly validate save paths supplied by
  paired peers in the manifest request handler. Attackers can specify arbitrary
  directories outside configured save locations to read and write files through
  manifest…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-73
vendor: Liquid-co
product: OpenSave
affected:
  - OpenSave <= 2.4.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:17:09.393'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103398'
references:
  - url: 'https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Liquid-co/OpenSave'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Liquid-co/OpenSave/blob/v2.4.0/internal/delta/rootguard.go#L16-L30
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Liquid-co/OpenSave/blob/v2.4.0/internal/p2p/routes.go#L555-L566
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/opensave-through-2.4.0-arbitrary-file-read-and-write-via-peer-controlled-save-path
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-30T15:37:56.394331Z'
ingestedAt: '2026-09-30T15:07:05.376Z'
---

## Overview

OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
