Directory Traversal Vulnerability in Perses Open-Source Dashboard and Visualization Tool
CVE-2026-63445

7.1HIGH

Key Information:

Vendor

Perses

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-63445?

The Perses Dashboard, an open-source project for visualizing observability data, contains a vulnerability that allows authenticated attackers to exploit improperly validated input in list endpoints associated with the file-system database. By injecting directory traversal characters into the project query parameter, an attacker can manipulate database paths, thereby accessing unauthorized YAML or JSON files and compromising project isolation. This flaw enables access to sensitive file-backed resources beyond the intended project directory. The issue has been addressed in version 0.54.0-rc.0.

Affected Version(s)

perses < 0.54.0-rc.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.