VYPR
Medium severity5.3NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026

CVE-2026-88940

CVE-2026-88940

Description

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Knowns Dev/Knownsreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.33.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.