Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm5p-8v8f-2vgm

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

EPSS

Процентиль: 39%
0.00464
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
13 дней назад

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

EPSS

Процентиль: 39%
0.00464
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-22