Ghostwire

CVE-2026-65702: Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration...

HIGH CVSS 0.0 EPSS 0.49%

Published: July 23, 2026 | Last Modified: July 24, 2026

Description

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from outside the intended store base directory. Attackers can supply path traversal sequences in the conversation_id parameter submitted to the unauthenticated chat API endpoints to escape the base directory during both write and read operations, enabling arbitrary file write with attacker-controlled content and unauthorized file read on the server filesystem.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.49% (39th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References