vulnti.work

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling dire…

Medium CVSS 6.8
CVECVE-2026-92812
First seen2026-09-19 03:16 UTC
Disclosed2026-09-16 21:17 UTC
Last updated2026-09-19 03:16 UTC
Channel statusauto

Summary

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD