PT-2026-94068 · Git+1 · Kraken

·

CVE-2026-92791

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Uber Kraken versions 0.1.0 through 0.1.29
Description An issue exists where the application fails to validate the tag parameter in the '/tags/{tag}' endpoint. This allows unauthenticated attackers to perform directory traversal by using percent-encoded parent-directory segments in the tag parameter, enabling the reading of arbitrary files accessible to the testfs backend process.
Recommendations Update Uber Kraken to a version later than 0.1.29. As a temporary mitigation, restrict access to the '/tags/{tag}' endpoint or avoid using the tag parameter until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92791

Affected Products

Kraken