Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-68705. PoCs published by imjdl.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2025-68705, a path traversal vulnerability in RustFS. The exploit uses gRPC calls to read arbitrary files on the server, with detailed usage examples and command-line arguments for customization.
Description
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79.
Exploits (1)
This repository contains a functional Python exploit for CVE-2025-68705, a path traversal vulnerability in RustFS. The exploit uses gRPC calls to read arbitrary files on the server, with detailed usage examples and command-line arguments for customization.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H