{"id":"CVE-2025-68705","aliases":["GHSA-pq29-69jg-9mxc"],"url":"https://o3.security/vulnerability/CVE-2025-68705","summary":"RustFS Path Traversal Vulnerability","details":"RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79.","published":"2026-01-07T20:31:44.236Z","modified":"2026-08-12T03:51:20.814853103Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"rustfs","fixedVersion":"1.0.0-alpha.79"}],"fix":{"url":"https://github.com/rustfs/rustfs/commit/ab752458ce431c6397175d167beee2ea00507d3e","label":"rustfs/rustfs@ab75245"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68705.json"},{"type":"ADVISORY","url":"https://github.com/rustfs/rustfs/security/advisories/GHSA-pq29-69jg-9mxc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68705"},{"type":"FIX","url":"https://github.com/rustfs/rustfs/commit/ab752458ce431c6397175d167beee2ea00507d3e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.814853103Z"}}