PatchSiren

kyndryl-open-source CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH kyndryl-open-source CVE published 2026-07-31

CVE-2026-55100

The hashi-vault-js module for Node.js, prior to version 0.5.2, contains a vulnerability that allows for path traversal and query parameter injection attacks. This issue arises from the improper encoding of identifier values in Vault request paths and query strings. The vulnerability was addressed in version 0.5.2, where the fix involved utilizing encodeURIComponent() and URLSearchParams for proper encodin [truncated]