Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfp3-v2gw-7wfq

Опубликовано: 25 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

Summary

Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization.

Details

Root cause 1 — router.go lines 798-802: The router uses req.URL.RawPath for route matching when useEscapedPathForRouting is false (the default). This means /admin%2Fsecret.txt is treated as a single path segment and does NOT match the /admin/* route pattern.

if !r.useEscapedPathForRouting && req.URL.RawPath != "" { path = req.URL.RawPath }

Root cause 2 — echo.go lines 559-568: StaticDirectoryHandler calls url.PathUnescape() on the path parameter before opening files. This converts %2F back to /, resolving admin/secret.txt on disk.

if !disablePathUnescaping { tmpPath, err := url.PathUnescape(p) p = tmpPath } name := filepath.ToSlash(filepath.Clean(strings.TrimPrefix(p, "/")))

PoC (Screenshot)

Sample: image

403: image

Bypass with encoded slash: image

Impact

Unauthorized static file disclosure. Applications that protect route prefixes with authentication middleware while also serving static files from a broader root are vulnerable. An attacker only needs to encode the slash (/%2F) in the URL to bypass all route-level protection.

Common affected pattern:

adminGroup := e.Group("/admin", authMiddleware) e.StaticFS("/", os.DirFS("public"))

Пакеты

Наименование

github.com/labstack/echo/v5

go
Затронутые версииВерсия исправления

< 5.2.0

5.2.0

Наименование

github.com/labstack/echo/v4

go
Затронутые версииВерсия исправления

< 4.15.3

4.15.3

Наименование

github.com/labstack/echo

go
Затронутые версииВерсия исправления

<= 3.3.10

Отсутствует

EPSS

Процентиль: 36%
0.00431
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
redhat
3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
nvd
3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

CVSS3: 7.5
debian
3 месяца назад

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router a ...

EPSS

Процентиль: 36%
0.00431
Низкий

7.5 High

CVSS3

Дефекты

CWE-22