Bug 2538845 (CVE-2026-63445) - CVE-2026-63445 github.com/perses/perses: Perses: Information disclosure via filesystem path traversal
Summary: CVE-2026-63445 github.com/perses/perses: Perses: Information disclosure via f...
Keywords:
Status: NEW
Alias: CVE-2026-63445
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 20:53 UTC by OSIDB Bzimport
Modified: 2026-09-23 08:02 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 20:53:29 UTC
Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query structure without validating it against directory traversal characters, and the resulting project value is used to select database paths. An authenticated attacker can supply directory traversal segments to leave the intended project directory, read arbitrary YAML or JSON files accessible to the Perses process, and bypass project isolation to enumerate other file-backed resources. This issue is fixed in version 0.54.0-rc.0.


Note You need to log in before you can comment on or make changes to this bug.