PT-2026-30894 · Emissary · Emissary

Brennantm

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-35583

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Emissary versions prior to 8.39.0
Description Emissary is a P2P based data-driven workflow engine. Prior to version 8.39.0, the configuration API endpoint /api/configuration/{name} validated configuration names using a blacklist approach that checked for , /, .., and trailing .. This validation could be bypassed using URL-encoded variants, double-encoding, or Unicode normalization, potentially leading to path traversal and the ability to read configuration files outside the intended directory.
Recommendations Update to version 8.39.0 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35583
GHSA-HXF2-GM22-7VCM

Affected Products

Emissary