CVE-2026-55100 with a CVSS score of 8.7 is a vulnerability in the hashi-vault-js library due to lack of proper encoding of identifiers in path segments and query strings, allowing attackers to manipulate the request URL and potentially access unintended downstream endpoints or inject malicious parameters if untrusted input is passed to the library. The flaw type is a path traversal and query string injection, which can be exploited by passing manipulated inputs to the library's methods, and it has a significant business impact as applications where Vault identifiers originate from untrusted user input allow an unauthenticated attacker to redirect requests to unintended Vault endpoints or otherwise alter the executed query, executing operations within the permissions of the Vault token used by the application. The affected versions are hashi-vault-js: <= 0.5.1.
We recommend you to update hashi-vault-js to version 0.5.2.[/subscribe_to_unlock_form]
CVE-2026-55100 with a CVSS score of 8.7 is a vulnerability in the hashi-vault-js library due to lack of proper encoding of identifiers in path segments and query strings, allowing attackers to manipulate the request URL and potentially access unintended downstream endpoints or inject malicious parameters if untrusted input is passed to the library. The flaw type is a path traversal and query string injection, which can be exploited by passing manipulated inputs to the library's methods, and it has a significant business impact as applications where Vault identifiers originate from untrusted user input allow an unauthenticated attacker to redirect requests to unintended Vault endpoints or otherwise alter the executed query, executing operations within the permissions of the Vault token used by the application. The affected versions are hashi-vault-js: <= 0.5.1.
We recommend you to update hashi-vault-js to version 0.5.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]