Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process. | |
| Title | Uber Kraken through 0.1.29 Path Traversal via tag parameter | |
| First Time appeared |
Uber
Uber kraken |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uber
Uber kraken |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:46.839Z
Reserved: 2026-09-16T19:40:19.438Z
Link: CVE-2026-92791
No data.
Status : Received
Published: 2026-09-16T21:17:28.627
Modified: 2026-09-16T21:17:28.627
Link: CVE-2026-92791
No data.
OpenCVE Enrichment
No data.
Weaknesses