Directory Traversal Vulnerability in Perses Open-Source Dashboard and Visualization Tool
CVE-2026-63445
7.1HIGH
What is CVE-2026-63445?
The Perses Dashboard, an open-source project for visualizing observability data, contains a vulnerability that allows authenticated attackers to exploit improperly validated input in list endpoints associated with the file-system database. By injecting directory traversal characters into the project query parameter, an attacker can manipulate database paths, thereby accessing unauthorized YAML or JSON files and compromising project isolation. This flaw enables access to sensitive file-backed resources beyond the intended project directory. The issue has been addressed in version 0.54.0-rc.0.
Affected Version(s)
perses < 0.54.0-rc.0
