HIGH
kyndryl-open-source
CVE published 2026-07-31
CVE-2026-55100
The hashi-vault-js module for Node.js, prior to version 0.5.2, contains a vulnerability that allows for path traversal and query parameter injection attacks. This issue arises from the improper encoding of identifier values in Vault request paths and query strings. The vulnerability was addressed in version 0.5.2, where the fix involved utilizing encodeURIComponent() and URLSearchParams for proper encodin [truncated]