CVE-2026-49233: Routinator has cache path traversal when processing the module component of rsync URIs
(updated )
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49233 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →