PT-2026-48673 · Perry · Perry

·

CVE-2026-53777

·

Published

2026-06-11

·

Updated

2026-06-11

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Perry versions prior to 0.5.1159
Description A path traversal issue exists where a malicious build server can write arbitrary content to any location writable by the running process. This occurs when unsanitized path components are supplied in the artifact name field of ArtifactReady WebSocket messages. Attackers who control the server URL can deliver traversal payloads through the artifact name or download path fields, leading to the overwriting of sensitive files or the exposure of arbitrary local files to a location accessible by the attacker.
Recommendations Update to version 0.5.1159 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53777
GHSA-X55V-Q459-68CH

Affected Products

Perry