Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process. | |
| Title | Uber Kraken through 0.1.29 Path Traversal via tag parameter | |
| First Time appeared |
Uber
Uber kraken |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uber
Uber kraken |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T15:41:40.643Z
Reserved: 2026-09-16T19:40:19.438Z
Link: CVE-2026-92791
Updated: 2026-09-21T15:41:15.296Z
Status : Received
Published: 2026-09-16T21:17:28.627
Modified: 2026-09-21T16:17:27.380
Link: CVE-2026-92791
No data.
OpenCVE Enrichment
Updated: 2026-09-18T09:15:06Z