CVE-2026-85665

Source
https://cve.org/CVERecord?id=CVE-2026-85665
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85665.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85665
Published
2026-09-04T14:32:21.592Z
Modified
2026-09-06T03:47:20.210858205Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Bruno through 4.1.0 Arbitrary File Read via Unconfined Body File Path
Details

Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection directory, causing the application to read and exfiltrate arbitrary files to attacker-controlled endpoints.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85665.json"
}
References

Affected packages

Git / github.com/usebruno/bruno

Affected ranges

Type
GIT
Repo
https://github.com/usebruno/bruno
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.1.0"
        },
        {
            "fixed": "3.4.2"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.12.0
v0.12.1
v0.12.2
v0.13.0
v0.13.1
v0.13.2
v0.14.0
v0.14.1
v0.15.0
v0.15.1
v0.15.2
v0.15.3
v0.16.0
v0.16.1
v0.16.2
v0.16.3
v0.16.4
v0.16.5
v0.16.6
v0.17.0
v0.18.0
v0.19.0
v0.2.0
v0.20.0
v0.21.0
v0.21.1
v0.22.0
v0.22.1
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.27.1
v0.27.2
v0.27.3
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.7.2
v0.8.0
v0.8.1
v0.8.2
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v1.*
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.10.0
v1.11.0
v1.12.0
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.16.0
v1.16.1
v1.17.0
v1.18.0
v1.18.1
v1.19.0
v1.2.0
v1.20.0
v1.20.1
v1.20.2
v1.20.3
v1.20.4
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.24.0
v1.25.0
v1.26.0
v1.26.1
v1.26.2
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.30.1
v1.31.0
v1.32.0
v1.32.1
v1.33.0
v1.33.1
v1.34.0
v1.34.1
v1.34.2
v1.36.0
v1.36.1
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.39.1
v1.4.0
v1.40.0
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.7.0
v1.7.1
v1.8.0
v1.9.0
v2.*
v2.0.0
v2.0.1
v2.1.0
v2.13.0
v2.13.1
v2.14.0
v2.14.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.8.0
v2.9.0
v3.*
v3.0.0
v3.0.1
v3.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85665.json"