The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either filepath.Join(d.root, key) or filepath.Clean(d.root + key) with no check that the result stayed beneath the root. Put, Get, Head, Delete, Chmod, Chown, Symlink and Readlink all consumed that value directly. Object keys enumera [truncated]
The CVE-2026-59092 record describes an authentication bypass vulnerability in JuiceFS through version 1.3.1, which allows unauthenticated remote attackers to access sensitive debug and metrics endpoints. This vulnerability is rated HIGH with a CVSS score of 7. The issue was fixed in commit a46979c. The vulnerability enables attackers to request the /debug/pprof/cmdline endpoint to obtain the process comma [truncated]