Path Traversal Vulnerability in Uber Kraken for Unauthenticated Attackers
CVE-2026-92791
8.7HIGH
What is CVE-2026-92791?
Uber Kraken versions up to 0.1.29 exhibit a flaw in the validation of the tag parameter within the /tags/{tag} endpoint. This vulnerability allows unauthenticated attackers to exploit the system by traversing outside the designated storage root. By leveraging percent-encoded parent-directory segments in the tag parameter, malicious users can gain unauthorized access to arbitrary files within the testfs backend process, potentially exposing sensitive information.
Affected Version(s)
kraken 0 <= 0.1.29
