Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-49380

CVE-2024-49380: Plenti Static Site Generator RCE Vulnerability

CVE-2024-49380 is a remote code execution vulnerability in Plenti static site generator caused by arbitrary file write in the /postLocal endpoint. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2024-49380 Overview

CVE-2024-49380 is an arbitrary file write vulnerability in Plenti, an open-source static site generator written in Go. The flaw affects all versions prior to 0.7.2 and resides in the /postLocal endpoint exposed when a Plenti user serves their website locally. An unauthenticated network attacker can write arbitrary files to the filesystem, which can lead to Remote Code Execution (RCE). The issue is tracked under [CWE-74] (Injection) and [CWE-78] (OS Command Injection) and was addressed in Plenti v0.7.2.

Critical Impact

Unauthenticated attackers reaching the local Plenti serve endpoint can write arbitrary files and achieve remote code execution on the host running the site generator.

Affected Products

  • Plenti static site generator versions prior to 0.7.2
  • Plenti cmd/serve.go/postLocal HTTP handler
  • Any developer or CI environment running plenti serve and exposing the local server

Discovery Timeline

  • 2024-10-25 - CVE-2024-49380 published to the National Vulnerability Database
  • 2024-10-25 - GitHub Security Advisory GHSL-2024-297 released alongside Plenti v0.7.2
  • 2025-05-06 - Last updated in NVD database

Technical Details for CVE-2024-49380

Vulnerability Analysis

Plenti exposes an HTTP server through the plenti serve command to support local content editing and previews. The /postLocal endpoint accepts a client-supplied file path and writes attacker-controlled content to that path on disk. The handler does not validate or canonicalize the destination, nor does it confine writes to the project directory.

Because the endpoint requires no authentication, any network-reachable client can invoke it. Writing into directories that influence code execution, such as the project content/ tree, build scripts, or shell startup files, results in arbitrary code execution the next time the affected file is consumed.

Root Cause

The root cause is missing input validation on the file path parameter passed to the /postLocal handler in cmd/serve.go. The handler treats the supplied path as trusted and passes it to file write operations without enforcing a base directory or rejecting traversal sequences such as ../. This pattern aligns with [CWE-74] (Improper Neutralization of Special Elements in Output) and contributes to the [CWE-78] command injection outcome when the written file is later interpreted as code.

Attack Vector

Exploitation requires only network access to the Plenti development server, typically bound to a local interface but frequently exposed in shared development, container, or cloud workspace environments. An attacker sends a crafted HTTP request to /postLocal containing a target path outside the intended content directory and a payload body. After the file is written, code execution is achieved by overwriting build scripts, JavaScript components rendered by the site, or operating system files such as ~/.bashrc. Refer to the GitHub Security Advisory GHSL-2024-297 and the vulnerable code in serve.go for full technical details.

Detection Methods for CVE-2024-49380

Indicators of Compromise

  • Unexpected HTTP POST requests to the /postLocal endpoint on hosts running plenti serve
  • New or modified files outside the Plenti project content/ directory, particularly in user home directories or system paths
  • Plenti process spawning shells, package managers, or network utilities not associated with normal builds

Detection Strategies

  • Monitor process telemetry for plenti child processes that execute interpreters such as sh, bash, node, or python
  • Inspect web server and reverse proxy logs for requests to /postLocal originating from non-local IP addresses
  • Alert on file integrity changes to shell profile scripts, cron files, and Plenti build configuration during a serve session

Monitoring Recommendations

  • Track outbound network connections from hosts running Plenti development servers for signs of post-exploitation
  • Audit running Plenti versions across developer endpoints and CI runners to ensure 0.7.2 or later is in use
  • Centralize developer workstation logs to detect anomalous file writes during static site builds

How to Mitigate CVE-2024-49380

Immediate Actions Required

  • Upgrade Plenti to version 0.7.2 or later on all developer workstations, build agents, and servers
  • Stop any long-running plenti serve processes until upgraded, especially those reachable from non-loopback interfaces
  • Review filesystems on hosts that ran vulnerable Plenti versions for unauthorized file writes

Patch Information

The fix is included in Plenti release v0.7.2, which adds path validation to the /postLocal handler. Details are documented in GitHub Security Advisory GHSL-2024-297.

Workarounds

  • Bind the Plenti development server strictly to 127.0.0.1 and avoid port-forwarding it through tunnels or shared environments
  • Run plenti serve only inside isolated containers or virtual machines without sensitive credentials on disk
  • Place the development server behind an authenticating reverse proxy that blocks external access to the /postLocal endpoint
bash
# Upgrade Plenti to the patched release
go install github.com/plentico/plenti@v0.7.2

# Verify the installed version is 0.7.2 or later
plenti --version

# Restrict the development server to the loopback interface
plenti serve --port 3000 # ensure firewall blocks external access to this port

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.