THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g956-2f74-rmv7 (high) — hashi-vault-js has a path traversal and query parameter injection

[GHSA] GHSA-g956-2f74-rmv7 (high) — hashi-vault-js has a path traversal and query parameter injection

medgithub_advisoriesPublished 2026-07-31

GHSA-g956-2f74-rmv7 Severity: high CVE: CVE-2026-55100

hashi-vault-js has a path traversal and query parameter injection

## Summary

The `hashi-vault-js` library is vulnerable to path traversal and query string injection due to the lack of proper encoding of identifiers in path segments and query strings. This allows attackers to manipulate the request URL and potentially access unintended downs

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g956-2f74-rmv7