Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process. | |
| Title | Uber Kraken through 0.1.29 Path Traversal via tag parameter | |
| First Time appeared |
Uber
Uber kraken |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uber
Uber kraken |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:46.839Z
Reserved: 2026-09-16T19:40:19.438Z
Link: CVE-2026-92791
No data.
No data.
No data.
OpenCVE Enrichment
No data.