๐Ÿ” CVE Alert

CVE-2026-55100

UNKNOWN 0.0

hashi-vault-js has a path traversal and query parameter injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.

CWE CWE-23 CWE-74
Vendor kyndryl-open-source
Product hashi-vault-js
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for kyndryl-open-source hashi-vault-js

Be the first to know when new unknown vulnerabilities affecting kyndryl-open-source hashi-vault-js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kyndryl-open-source / hashi-vault-js
< 0.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kyndryl-open-source/hashi-vault-js/security/advisories/GHSA-g956-2f74-rmv7 github.com: https://github.com/kyndryl-open-source/hashi-vault-js/pull/66 github.com: https://github.com/kyndryl-open-source/hashi-vault-js/commit/ea2f76052d366a08f35f62ef4c12b6a334c91ec2 github.com: https://github.com/kyndryl-open-source/hashi-vault-js/releases/tag/v0.5.2