Kontent.Ai.Management is vulnerable to Path Traversal
59
Medium Risk
The SDK builds Management API request paths by inserting caller-supplied identifiers such as codenames, emails, and upload file names directly into URL path segments. These values are not escaped or validated, so an identifier containing path-traversal sequences like ../ or / can change which Management API endpoint a request targets under the same API key. An application that forwards attacker-influenced identifier values into SDK calls can have its requests retargeted to unintended endpoints. The fix encodes and validates each identifier as a single URL path segment and rejects . and .. segments.
You are affected if you are using a version that falls within the vulnerable range and your application passes user-controlled or otherwise untrusted identifier values (such as codenames, emails, or upload file names) into SDK requests.
Kontent.Ai.Management is vulnerable to Path Traversal in versions 1.2.17 - 8.3.0.
Upgrade the Kontent.Ai.Management library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant