CVE-2026-63445: Perses's unvalidated project parameter enables filesystem path traversal
### Impact When Perses is using the file system database, on the list endpoints, the project value is bound from the request into the resource `Query` struct and is never validated against directory-traversal characters (validation/Flatten only runs for Create/Update bodies, not list queries). The path is then used to retrieve files in the database directly. Attacker can read arbitrary YAML/JSON files from the server host and can bypass the security constraints to get access to other resources contained in the file database. For example `https://localhost:8080/api/v1/dashboards?project=../projects` returns the list of the project while it must not return anything. ### Patches _Has the problem been patched? What versions should users upgrade to?_ ### Workarounds Avoid using the file system database in production. Use SQL database instead.
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/perses/perses 0.54.0-rc.0.
Technical details
- Vendor
- Not specified
- Product
- github.com/perses/perses
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source