CVE-2026-55100High▾ Twilighthashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
hashi-vault-js <= 0.5.1Patched in:
hashi-vault-js 0.5.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55102Medium· 5.8hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API
CVE-2022-27924High· 7.5Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance
CVE-2026-59149Medium· 6.5@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
CVE-2026-16729Medium· 4.8undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-50016High· 8.8pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
GHSA-jvcm-f35g-w78pMedium· 6.5Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory