CVE-2026-92812

HIGH CVSS 4.0: 7.6 EPSS 0.29%
Updated Sep 19, 2026
decap-server
Parameter Value
CVSS 7.6 (HIGH)
Type CWE-22 (Path Traversal)
Vendor decap-server
Public PoC No

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)