Impact
decap-server contains a directory traversal flaw stemming from a local proxy containment guard that performs plain string prefix comparison without validating the path separator. This omission allows an attacker to pick any sibling directory whose name starts with the repository name and then read, modify, or delete files outside the intended repository root. The vulnerability is classified as CWE‑22 and can compromise file system integrity, confidentiality, and potentially the availability of critical system files if the attacker can write or delete them.
Affected Systems
The affected component is the decap‑server library distributed by decaporg. No specific version range is listed in the advisory, so all current releases are considered vulnerable. Based on the description, it is inferred that the unsafe guard exists in the main codebase, meaning any deployment that exposes the local proxy endpoint to untrusted users is at risk. Administrators should determine whether their decap‑server instances are exposed to external traffic and confirm the exact version in use.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at present, and the flaw is not listed in the CISA KEV catalog. The path traversal requires that the attacker interacts with the local proxy endpoint, implying that either local code execution or remote access to the decap‑server instance is necessary. Based on the description, it is inferred that an attacker could exploit the flaw by crafting a specially crafted URL that bypasses the guard, after gaining access to the endpoint, and then traverse to arbitrary directories relative to the repository root.
OpenCVE Enrichment