{"id":"CVE-2026-40075","aliases":["GHSA-jjgj-cx3q-pw4w"],"url":"https://o3.security/vulnerability/CVE-2026-40075","summary":"OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet","details":"## Affected Versions\n\nversion ≤ 2.7.8 (latest version at time of disclosure)\n\nhttps://github.com/openmrs/openmrs-core\n\n## Impact\n\nThe `/openmrs/moduleResources/{moduleid}` endpoint in OpenMRS Core is vulnerable to a path traversal attack. The `ModuleResourcesServlet` does not properly validate user-supplied path input, allowing an attacker to traverse directories and read arbitrary files from the server filesystem (e.g., `/etc/passwd`, application configuration files containing database credentials).\n\nThis endpoint serves static module resources (CSS, JS, images) and is **not protected by authentication filters**, as these resources are required for rendering the login page. Therefore, this vulnerability can be exploited by an **unauthenticated** attacker.\n\n> **Note:** Successful exploitation requires the target deployment to run on **Apache Tomcat < 8.5.31**, where the `..;` path parameter bypass is not mitigated by the container. Deployments on Tomcat ≥ 8.5.31 / ≥ 9.0.10 are protected at the container level, though the underlying code defect remains.\n> \n\n## Steps to Reproduce\n\n1. Identify a valid installed module ID on the target OpenMRS instance (e.g., `legacyui`).\n2. Send the following HTTP request:\n\n<img width=\"1038\" height=\"798\" alt=\"image\" src=\"https://github.com/user-attachments/assets/7d10ee0e-4d81-4c01-bc84-a1bf5715f170\" />\n\n3. The server responds with HTTP 200 and the contents of `/etc/passwd`:\n\n<img width=\"1028\" height=\"843\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b6806a7e-ff52-4f51-8f7f-7ea4e9754d10\" />\n\n\n## Root Cause Analysis\n\nThe vulnerability exists in `ModuleResourcesServlet.java` (`web/src/main/java/org/openmrs/module/web/ModuleResourcesServlet.java`).\n\nThe `getFile()` method constructs a filesystem path from user-controlled input without performing path boundary validation:\n\n```java\nprotected File getFile(HttpServletRequest request) {\n    // Step 1: User-controlled path input\n    String path = request.getPathInfo();\n\n    // Step 2: Extract module from path prefix\n    Module module = ModuleUtil.getModuleForPath(path);\n    if (module == null) { return null; }\n\n    // Step 3: Strip module ID prefix — no traversal check\n    String relativePath = ModuleUtil.getPathForResource(module, path);\n\n    // Step 4: Concatenate into absolute path\n    String realPath = getServletContext().getRealPath(\"\")\n        + MODULE_PATH\n        + module.getModuleIdAsPath()\n        + \"/resources\"\n        + relativePath;  // contains \"/../../../etc/passwd\"\n\n    realPath = realPath.replace(\"/\", File.separator);\n\n    // Step 5: No normalize().startsWith() boundary check\n    File f = new File(realPath);\n    if (!f.exists()) { return null; }\n\n    return f;  // Arbitrary file returned to client\n}\n```\n\nThe helper method `ModuleUtil.getPathForResource()` only strips the module ID prefix and performs no sanitization:\n\n```java\npublic static String getPathForResource(Module module, String path) {\n    if (path.startsWith(\"/\")) {\n        path = path.substring(1);\n    }\n    return path.substring(module.getModuleIdAsPath().length());\n    // Returns unsanitized remainder, e.g., \"/../../../../../../etc/passwd\"\n}\n```\n\nThe resulting path resolves as:\n\n```\n{webapp}/WEB-INF/view/module/legacyui/resources/../../../../../../etc/passwd\n  → /etc/passwd\n```\n\nNotably, the same codebase already implements correct path traversal protection in `StartupFilter.java`:\n\n```java\n// StartupFilter.java — correct protection\nfullFilePath = fullFilePath.resolve(httpRequest.getPathInfo());\nif (!(fullFilePath.normalize().startsWith(filePath))) {\n    log.warn(\"Detected attempted directory traversal...\");\n    return;  // Request rejected\n}\n```\n\nThis check is absent from `ModuleResourcesServlet`.\n\n## Remediation\n\nAdd a path boundary check after constructing `realPath` and before returning the `File` object. The fix should use `normalize()` + `startsWith()` to ensure the resolved path stays within the allowed module resources directory:\n\n```java\nFile f = new File(realPath);\nPath allowedBase = Paths.get(getServletContext().getRealPath(\"\"), \"WEB-INF\", \"view\", \"module\");\nif (!f.toPath().normalize().startsWith(allowedBase.normalize())) {\n    log.warn(\"Blocked path traversal attempt: {}\", request.getPathInfo());\n    return null;\n}\n```\n\nThis is consistent with the existing pattern used in `StartupFilter.java` and `TestInstallUtil.java` within the same project.","published":"2026-05-05T21:25:41.993Z","modified":"2026-08-12T03:51:24.016174501Z","cvss":null,"epss":{"score":0.00558,"percentile":0.43721,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.openmrs.web:openmrs-web","fixedVersion":null},{"ecosystem":"Maven","name":"org.openmrs.web:openmrs-web","fixedVersion":"2.8.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40075.json"},{"type":"ADVISORY","url":"https://github.com/openmrs/openmrs-core/security/advisories/GHSA-jjgj-cx3q-pw4w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40075"},{"type":"PACKAGE","url":"https://github.com/openmrs/openmrs-core"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.016174501Z"}}