Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88940

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

EPSS

Процентиль: 39%
0.00464
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
github
13 дней назад

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

EPSS

Процентиль: 39%
0.00464
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22