CVE-2026-103398: OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path
Published Sep 30, 2026
·Updated
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.
Affected Software
1 affected component
OpenSave<=2.4.0
Event History
Sep 30, 2026
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an existing level of access?
Yes. The CVSS vector indicates low privileges are required, and the affected save paths are supplied by paired peers. The attack is network-accessible and does not require user interaction.
2
Is availability impact indicated by the reported severity data?
No availability impact is indicated in the CVSS vector. The reported impacts are high confidentiality and high integrity impact.