PatchSiren

decaporg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH decaporg CVE published 2026-09-16

CVE-2026-92812

A path traversal vulnerability exists in decap-server's local proxy containment guard due to plain string prefix comparison without path separator validation. This allows attackers to access sibling directories whose names begin with the repository directory name, enabling them to read, write, or delete files outside the intended repository root. The vulnerability has a high CVSS score of 7.6, indicating [truncated]