CVE-2026-34783Disclosure(montferret / ferret)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write arbitrary files to the filesystem of the machine running Ferret. When an operator scrapes a website that returns filenames containing ../ sequences, and uses those filenames to construct output paths (a standard scraping pattern), the attacker controls both the destination path and the file content. This can lead to remote code execution via cron jobs, SSH authorized_keys, shell profiles, or web shells. This vulnerability is fixed in 2.0.0-alpha.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ferret

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ferret

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-03: 1Mentions · 2026-04-06: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-06: 104-0304-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🔓 CVE-2026-34783: Ferret path traversal in IO::FS::WRITE for arbitrary writes. Severity: High. Published: 2026-04-03. Source: https://www.tenable.com/cve/newest

    Post summary

    A newly disclosed high‑severity vulnerability, CVE‑2026‑34783, is a path‑traversal flaw in Ferret’s IO::FS::WRITE module that allows arbitrary writes.

    2005059
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34783 Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function a… https://www.cve.org/CVERecord?id=CVE-2026-34783

    Post summary

    The post discloses a path traversal vulnerability affecting Ferret’s IO::FS::WRITE function before version 2.0.0‑alpha.4, but does not provide PoC, exploit code, or patch details.

    00000124
    57.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmontferretferret-go-
Appmontferretferret2.0.0go-
Appmontferretferret2.0.0go-
Appmontferretferret2.0.0go-

Explore more