Description
decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.
Published: 2026-09-16
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Directory traversal enabling unauthorized file read, write, or delete outside the repository root
Action: Assess Impact
AI Analysis

Impact

decap-server contains a directory traversal flaw stemming from a local proxy containment guard that performs plain string prefix comparison without validating the path separator. This omission allows an attacker to pick any sibling directory whose name starts with the repository name and then read, modify, or delete files outside the intended repository root. The vulnerability is classified as CWE‑22 and can compromise file system integrity, confidentiality, and potentially the availability of critical system files if the attacker can write or delete them.

Affected Systems

The affected component is the decap‑server library distributed by decaporg. No specific version range is listed in the advisory, so all current releases are considered vulnerable. Based on the description, it is inferred that the unsafe guard exists in the main codebase, meaning any deployment that exposes the local proxy endpoint to untrusted users is at risk. Administrators should determine whether their decap‑server instances are exposed to external traffic and confirm the exact version in use.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at present, and the flaw is not listed in the CISA KEV catalog. The path traversal requires that the attacker interacts with the local proxy endpoint, implying that either local code execution or remote access to the decap‑server instance is necessary. Based on the description, it is inferred that an attacker could exploit the flaw by crafting a specially crafted URL that bypasses the guard, after gaining access to the endpoint, and then traverse to arbitrary directories relative to the repository root.

Generated by OpenCVE AI on September 18, 2026 at 06:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict external access to the decap-server service by placing it behind an internal firewall or limiting it to trusted networks, thereby reducing exposure to untrusted inputs.
  • Apply the latest security release from decaporg or, if no patch is currently available, disable the local proxy feature until a fixed version is released.
  • Enforce strict file system permissions on directories served by decap-server, ensuring that only the minimal required user has write or delete rights and that read access is denied to unauthorized locations.
  • Configure the proxy to reject requests containing ‘..’ segments or enforce path normalization before routing, as a temporary mitigation until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Decaporg
Decaporg decap-server
Vendors & Products Decaporg
Decaporg decap-server

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.
Title decap-server Path Traversal via Sibling Directory Prefix Matching
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Decaporg Decap-server
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T01:53:35.949Z

Reserved: 2026-09-16T19:55:01.700Z

Link: CVE-2026-92812

cve-icon Vulnrichment

Updated: 2026-09-19T01:53:31.095Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:31.017

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')