THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vr5f-w35q-98jp (high) — Perses's unvalidated project parameter enables filesystem path traversal

[GHSA] GHSA-vr5f-w35q-98jp (high) — Perses's unvalidated project parameter enables filesystem path traversal

medgithub_advisoriesPublished 2026-09-18

GHSA-vr5f-w35q-98jp Severity: high CVE: CVE-2026-63445

Perses's unvalidated project parameter enables filesystem path traversal

### Impact When Perses is using the file system database, on the list endpoints, the project value is bound from the request into the resource `Query` struct and is never validated against directory-traversal characters (validation/Flatten only runs for Create/Update b

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vr5f-w35q-98jp