HIGH
decaporg
CVE published 2026-09-16
CVE-2026-92812
A path traversal vulnerability exists in decap-server's local proxy containment guard due to plain string prefix comparison without path separator validation. This allows attackers to access sibling directories whose names begin with the repository directory name, enabling them to read, write, or delete files outside the intended repository root. The vulnerability has a high CVSS score of 7.6, indicating [truncated]