PT-2026-20330 · Echo · Echo

Shblue21

·

Publicado

2026-02-17

·

Atualizado

2026-03-03

·

CVE-2026-25766

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Echo versions 5.0.0 through 5.0.2
Description Echo, a Go web framework, has an issue where the middleware.Static component, when used with the default filesystem on Windows, allows path traversal through backslashes. This enables unauthenticated remote file read outside the designated static root. The requested path is processed using path.Clean, which does not recognize backslashes as path separators, leaving .. sequences intact. Subsequently, os.Open on Windows interprets these backslashes as separators, enabling traversal beyond the intended static root. The middleware/static.go file and the echo.go file are relevant to this issue.
Recommendations Update to Echo version 5.0.3 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25766
GHSA-PGVM-WXW2-HRV9
GO-2026-4502
SUSE-SU-2026:0757-1

Produtos afetados

Echo