CVE-2026-66381: Repository readers may access content outside configured upstream paths
Published Aug 12, 2026
·Updated
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
Event History
Aug 12, 2026
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66381?
The severity of CVE-2026-66381 is medium with a score of 5.3.
2
What does CVE-2026-66381 describe?
CVE-2026-66381 describes an issue where repository readers may access content outside configured upstream paths under specific conditions.
3
What type of vulnerability is CVE-2026-66381 classified as?
CVE-2026-66381 is classified as a Path Traversal vulnerability.
4
How can I mitigate the risks associated with CVE-2026-66381?
Mitigation for CVE-2026-66381 involves reviewing and restricting cache-deploy permissions in your repository configurations.
5
When was CVE-2026-66381 published?
CVE-2026-66381 was published on August 12, 2026.