Impact
The vulnerability resides in the /tags/{tag} endpoint of Uber Kraken, which does not validate the tag parameter. By supplying percent‑encoded parent‑directory segments, an attacker can escape the configured storage root and read arbitrary files that the testfs backend process can access. This enables the disclosure of sensitive data, including configuration files or credentials, thereby compromising confidentiality.
Affected Systems
Uber Kraken products prior to version 0.1.30 are affected. The issue exists in all releases up to and including 0.1.29 of the Uber Kraken project.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is considered high severity. The EPSS score of less than 1% indicates that exploitation is unlikely but not impossible, and the vulnerability is not listed in the CISA KEV catalog. Attackers do not need authentication and can trigger the vulnerability by sending arbitrary requests to the public /tags endpoint. The primary impact is the unauthorized reading of files, which threatens confidentiality but does not directly alter data or crash the service.
OpenCVE Enrichment