OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-63445: Perses's unvalidated project parameter enables filesystem path traversal

GitHub Advisories · officialPublished Sep 18, 2026Risk 37/100

### Impact When Perses is using the file system database, on the list endpoints, the project value is bound from the request into the resource `Query` struct and is never validated against directory-traversal characters (validation/Flatten only runs for Create/Update bodies, not list queries). The path is then used to retrieve files in the database directly. Attacker can read arbitrary YAML/JSON files from the server host and can bypass the security constraints to get access to other resources contained in the file database. For example `https://localhost:8080/api/v1/dashboards?project=../projects` returns the list of the project while it must not return anything. ### Patches _Has the problem been patched? What versions should users upgrade to?_ ### Workarounds Avoid using the file system database in production. Use SQL database instead.

Upgrade affected packages to a patched version: github.com/perses/perses 0.54.0-rc.0.

Vendor
Not specified
Product
github.com/perses/perses
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source