CVE-2026-53777
HIGHDescription
Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact_name or download_path fields, causing the client to overwrite sensitive files or expose arbitrary local files to an attacker-accessible location.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploit Intelligence
Low risk: more likely to be exploited than 30% of all known CVEs.
References
- https://github.com/PerryTS/perry/commit/95e1043df8081f67038bffce847dd9ddb3dae046
- https://github.com/PerryTS/perry/pull/4989
- https://github.com/PerryTS/perry/releases/tag/v0.5.1159
- https://github.com/PerryTS/perry/security/advisories/GHSA-x55v-q459-68ch
- https://www.vulncheck.com/advisories/perry-path-traversal-via-artifactready-websocket
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-06-11.