THREAT OPS › Threat News › [GHSA] GHSA-vr5f-w35q-98jp (high) — Perses's unvalidated project parameter enables filesystem path traversal
[GHSA] GHSA-vr5f-w35q-98jp (high) — Perses's unvalidated project parameter enables filesystem path traversal
GHSA-vr5f-w35q-98jp Severity: high CVE: CVE-2026-63445
Perses's unvalidated project parameter enables filesystem path traversal
### Impact When Perses is using the file system database, on the list endpoints, the project value is bound from the request into the resource `Query` struct and is never validated against directory-traversal characters (validation/Flatten only runs for Create/Update b
Indicators of compromise
- CVE-2026-63445cve
Original source: https://github.com/advisories/GHSA-vr5f-w35q-98jp