CVE-2026-55100 | kyndryl-open-source hashi-vault-js up to 0.5.1 Request Path Construction src/Vault.js encodeURIComponent name/username/group/role/version path traversal
A vulnerability marked as critical has been reported in kyndryl-open-source hashi-vault-js up to 0.5.1. Affected is the function encodeURIComponent of the file src/Vault.js of the component Request Path Construction. The manipulation of the argument name/username/group/role/version leads to path traversal.
This vulnerability is traded as CVE-2026-55100. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More