CVE-2026-92812

Source
https://cve.org/CVERecord?id=CVE-2026-92812
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92812.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92812
Published
2026-09-16T20:32:58Z
Modified
2026-10-08T02:52:45Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
decap-server Path Traversal via Sibling Directory Prefix Matching
Details

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92812.json"
}
References

Affected packages

Git / github.com/decaporg/decap-cms

Affected ranges

Type
GIT
Repo
https://github.com/decaporg/decap-cms
Events

Affected versions

Other
11f35405cd1a1d1216e97b890173f46436752019

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92812.json"