CVE-2026-102811: Marmite through 0.4.2 Unauthenticated API Access via Development Server
Marmite through 0.4.2 contains missing authentication in the development server endpoints /marmite/content, /marmite/config, and /marmite/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handlecreatecontent and handleclonecontent to write files outside the project directory via directory traversal.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments running Marmite's development server are exposed if its development endpoints are reachable by an attacker. The affected endpoints include /__marmite__/content, /__marmite__/config, and /__marmite__/file/.
Does exploitation require credentials or user interaction?
No. The vulnerability is unauthenticated, and the provided vector indicates network-based exploitation with low attack complexity and no user interaction.
What can an attacker do?
An attacker can create, modify, or overwrite site content and configuration through the development server endpoints. Unsanitized path parameters in content creation and cloning can also be used for directory traversal to write files outside the project directory.