HIGH 7.6 NVD

CVE-2026-92812

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator valida

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

References

Published: 2026-09-16 · Source: NVD · Feed updated: 2026-09-16
This high severity vulnerability with a CVSS score of 7.6 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.