PatchSiren

juicedata CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH juicedata CVE published 2026-08-21

CVE-2026-77763

The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either filepath.Join(d.root, key) or filepath.Clean(d.root + key) with no check that the result stayed beneath the root. Put, Get, Head, Delete, Chmod, Chown, Symlink and Readlink all consumed that value directly. Object keys enumera [truncated]

HIGH juicedata CVE published 2026-07-02

CVE-2026-59092

The CVE-2026-59092 record describes an authentication bypass vulnerability in JuiceFS through version 1.3.1, which allows unauthenticated remote attackers to access sensitive debug and metrics endpoints. This vulnerability is rated HIGH with a CVSS score of 7. The issue was fixed in commit a46979c. The vulnerability enables attackers to request the /debug/pprof/cmdline endpoint to obtain the process comma [truncated]