CVE-2023-38337: Rswag Project Rswag

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.

Affected products

Published 2023-07-14. Last modified 2026-06-17.