THREAT OPS › Threat News › [GHSA] GHSA-g956-2f74-rmv7 (high) — hashi-vault-js has a path traversal and query parameter injection
[GHSA] GHSA-g956-2f74-rmv7 (high) — hashi-vault-js has a path traversal and query parameter injection
GHSA-g956-2f74-rmv7 Severity: high CVE: CVE-2026-55100
hashi-vault-js has a path traversal and query parameter injection
## Summary
The `hashi-vault-js` library is vulnerable to path traversal and query string injection due to the lack of proper encoding of identifiers in path segments and query strings. This allows attackers to manipulate the request URL and potentially access unintended downs
Indicators of compromise
- CVE-2026-55100cve
Original source: https://github.com/advisories/GHSA-g956-2f74-rmv7