An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
References
| Link | Resource |
|---|---|
| https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases | Release Notes Vendor Advisory |
| https://docs.jfrog.com/releases/docs/jfrog-security-advisories | Vendor Advisory |
| https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf | Technical Description |
| https://openai.com/index/hugging-face-incident-and-the-road-ahead/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-66384 | US Government Resource |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-12 16:17
Updated : 2026-08-28 12:21
NVD link : CVE-2026-66384
Mitre link : CVE-2026-66384
CVE.ORG link : CVE-2026-66384
JSON object : View
Products Affected
jfrog
- artifactory
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
