Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjm6-6gxh-mvf2

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 6.8

Описание

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

7.6 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.8
nvd
1 день назад

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

7.6 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-22