CVE-2026-88940

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 16:18

Updated : 2026-09-10 19:58


NVD link : CVE-2026-88940

Mitre link : CVE-2026-88940

CVE.ORG link : CVE-2026-88940


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')