CVE-2026-55100
hashi-vault-js has a path traversal and query parameter injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.
| CWE | CWE-23 CWE-74 |
| Vendor | kyndryl-open-source |
| Product | hashi-vault-js |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for kyndryl-open-source hashi-vault-js
Be the first to know when new unknown vulnerabilities affecting kyndryl-open-source hashi-vault-js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
kyndryl-open-source / hashi-vault-js
< 0.5.2
References
github.com: https://github.com/kyndryl-open-source/hashi-vault-js/security/advisories/GHSA-g956-2f74-rmv7 github.com: https://github.com/kyndryl-open-source/hashi-vault-js/pull/66 github.com: https://github.com/kyndryl-open-source/hashi-vault-js/commit/ea2f76052d366a08f35f62ef4c12b6a334c91ec2 github.com: https://github.com/kyndryl-open-source/hashi-vault-js/releases/tag/v0.5.2