Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. hashi-vault-js
  4. ›
  5. CVE-2026-55100

CVE-2026-55100: hashi-vault-js has a path traversal and query parameter injection

July 31, 2026

The hashi-vault-js library is vulnerable to path traversal and query string injection due to the lack of proper encoding of identifiers in path segments and query strings. This allows attackers to manipulate the request URL and potentially access unintended downstream endpoints or inject malicious parameters if untrusted input is passed to the library.

References

  • github.com/advisories/GHSA-g956-2f74-rmv7
  • github.com/kyndryl-open-source/hashi-vault-js/commit/ea2f76052d366a08f35f62ef4c12b6a334c91ec2
  • github.com/kyndryl-open-source/hashi-vault-js/pull/66
  • github.com/kyndryl-open-source/hashi-vault-js/releases/tag/v0.5.2
  • github.com/kyndryl-open-source/hashi-vault-js/security/advisories/GHSA-g956-2f74-rmv7
  • nvd.nist.gov/vuln/detail/CVE-2026-55100

Code Behaviors & Features

Detect and mitigate CVE-2026-55100 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.5.2

Fixed versions

  • 0.5.2

Solution

Upgrade to version 0.5.2 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-23: Relative Path Traversal
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Source file

npm/hashi-vault-js/CVE-2026-55100.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:24 +0000.