github.com/kumahq/kuma/v2 is vulnerable to Path Traversal
75
High Risk
Affected versions of this package are vulnerable to file inclusion due to insufficient validation of file paths used by secure data sources. The control plane allows reading data from filesystem paths without properly restricting traversal sequences or enforcing absolute paths, allowing an attacker with configuration control to reference unintended files on the host system. This could result in unauthorized access to sensitive local files. The issue is fixed by validating file paths, rejecting directory traversal sequences, and requiring absolute paths before reading files.
You are affected if you are using a version that falls within the vulnerable range.
github.com/kumahq/kuma/v2 is vulnerable to Path Traversal in versions 2.0.0 - 2.12.5 and 2.13.0 - 2.13.0.
Upgrade the github.com/kumahq/kuma/v2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant