PatchSiren

orhun CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH orhun CVE published 2026-09-13

CVE-2026-90774

CVE-2026-90774 debrief: rustypaste path traversal via filename header allows attackers to bypass directory-escape checks and write files outside the configured upload directory, potentially impacting data integrity, confidentiality, and system availability. Defenders responsible for systems using rustypaste should assess exposure and prioritize verification and remediation. The vulnerability exists in rus [truncated]