{"id":"GHSA-8v2v-wjwg-vx6r","summary":"actix-files has a possible exposure of information vulnerability","details":"### Summary\n\nWhen passing a non-existing folder to the `actix_files::Files::new()` method causes the actix server to expose unexpected files.\n\n### Details\n\nThe `actix-files` library exposes a [`Files` struct](https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/files.rs#L38) that configures an actix `service` to serve the files in a folder as static assets. Below you can find the [signature of the `Files::new` method](https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/files.rs#L98):\n\n```rust\npub fn new\u003cT: Into\u003cPathBuf\u003e\u003e(mount_path: &str, serve_from: T) -\u003e Files\n```\n\nWhen the `mount_path` you pass to `Files` doesn't exist, [it defaults to an empty path](https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/files.rs#L104) (`Path::new()`). When the service receives a HTTP request, it [joins the request information with the empty path](https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/service.rs#L136) and calls `canonicalize`. Rust resolves this path as relative and returns any file that matches it.\n\nThis behavior causes the library to expose unexpected files when the folder is not present.\n\n### PoC\n\n_There is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue_\n\n1. Clone the https://github.com/actix/examples repository.\n2. Change your directory to the `basics/static-files` folder.\n3. Edit the `src/main.rs` file and change the line 13 to mount a non-existing folder:\n\n    ```diff\n    -        .service(Files::new(\"/images\", \"static/images/\").show_files_listing())\n    +        .service(Files::new(\"/images\", \"static/missing/\").show_files_listing())\n    ```\n    \n4. Run the project with `cargo run`.\n5. Access the \u003chttp://localhost:8080/images/Cargo.toml\u003e URL.\n\n### Impact\n\nThis is an exposure of information vulnerability. It affects anyone using the `actix-files::Files` library that mounts a non-existing folder for any reason.","aliases":["CVE-2026-72814"],"modified":"2026-08-15T04:24:53.557265537Z","published":"2026-02-06T18:56:20Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-06T18:56:20Z","nvd_published_at":null,"cwe_ids":["CWE-200"]},"references":[{"type":"WEB","url":"https://github.com/actix/actix-web/security/advisories/GHSA-8v2v-wjwg-vx6r"},{"type":"PACKAGE","url":"https://github.com/actix/actix-web"},{"type":"WEB","url":"https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/files.rs#L104"},{"type":"WEB","url":"https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/files.rs#L38"},{"type":"WEB","url":"https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/files.rs#L98"},{"type":"WEB","url":"https://github.com/actix/actix-web/blob/fba766b4beb92278665d58815c94d336015225c5/actix-files/src/service.rs#L136"}],"affected":[{"package":{"name":"actix-files","ecosystem":"crates.io","purl":"pkg:cargo/actix-files"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.10"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.9","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8v2v-wjwg-vx6r/GHSA-8v2v-wjwg-vx6r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}