Relative Path Traversal Affecting privatebin/privatebin package, versions >=1.7.7, <2.0.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Relative Path Traversal vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-PRIVATEBINPRIVATEBIN-14038315
  • published16 Nov 2025
  • disclosed13 Nov 2025
  • creditBenoit Esnard

Introduced: 13 Nov 2025

NewCVE-2025-64714  (opens in a new tab)
CWE-23  (opens in a new tab)

How to fix?

Upgrade privatebin/privatebin to version 2.0.3 or higher.

Overview

privatebin/privatebin is a minimalist, open source online pastebin where the server has zero knowledge of pasted data.

Affected versions of this package are vulnerable to Relative Path Traversal via the template-switching feature when templateselection is enabled in the configuration. An attacker can read sensitive files or potentially execute arbitrary code by supplying crafted path traversal values in the template cookie.

Note: This is only exploitable if the templateselection setting is enabled in the configuration.

Workaround

This vulnerability can be mitigated by setting templateselection = false in the configuration file or removing the option entirely.

References

CVSS Base Scores

version 4.0
version 3.1