Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process. | |
| Title | Uber Kraken through 0.1.29 Path Traversal via tag parameter | |
| First Time appeared |
Uber
Uber kraken |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uber
Uber kraken |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:46.839Z
Reserved: 2026-09-16T19:40:19.438Z
Link: CVE-2026-92791
No data.
Status : Received
Published: 2026-09-16T21:17:28.627
Modified: 2026-09-16T21:17:28.627
Link: CVE-2026-92791
No data.
OpenCVE Enrichment
No data.
Weaknesses