CVE-2026-85665: Usebruno Bruno
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection directory, causing the application to read and exfiltrate arbitrary files to attacker-controlled endpoints.
Affected products
- Usebruno Bruno: up to and including 4.1.0
Published 2026-09-04. Last modified 2026-09-23.