CVE-2020-36565

MEDIUM

Labstack Echo <= 4.2.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

References (3)

Core 3

Scores

CVSS v3 5.3
EPSS 0.0134
EPSS Percentile 67.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
labstack/echo < 4.2.0
labstack/echo 0 - 4.2.0Go
Published Dec 07, 2022
Tracked Since Feb 18, 2026