[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-66384":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-27T23:51:06.732Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":40,"aliases":41,"duplicate_of":9,"upstream":42,"downstream":43,"duplicates":44,"related":45,"reserved_at":9,"published_at":46,"modified_at":47,"state":48,"summary":49,"references_raw":60,"kevs":86,"epss":97,"epss_history":99,"metrics":143,"affected":151},"CVE-2026-66384","An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],[],[],[],[],[],[],"2026-08-12T15:14:04.906Z","2026-08-27T19:58:24.244Z","Modified",{"cisa_kev":50,"cisa_ransomware":51,"cisa_vendor":52,"epss_severity":53,"epss_score":54,"severity":55,"severity_score":56,"severity_version":57,"severity_source":58,"severity_vector":59,"severity_status":48},true,false,"JFrog","low",0.00264,"medium",5.3,"v3.1","cve.org","CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",[61,67,72,77,81],{"url":62,"sources":63,"tags":65},"https://docs.jfrog.com/releases/docs/jfrog-security-advisories",[58,64],"nvd",[66],"Vendor Advisory",{"url":68,"sources":69,"tags":70},"https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",[58,64],[66,71],"Release Notes",{"url":73,"sources":74,"tags":75},"https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",[58,64],[76],"Third Party Advisory",{"url":78,"sources":79,"tags":80},"https://openai.com/index/hugging-face-incident-and-the-road-ahead/",[58,64],[76],{"url":82,"sources":83,"tags":84},"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-66384",[58,64],[85],"Government Resource",[87],{"source":88,"vendor":52,"product":89,"date_added":90,"vulnerability_name":91,"short_description":92,"required_action":93,"due_date":94,"known_ransomware_campaign_use":95,"notes":96,"exploitation_type":9},"cisa","Artifactory","2026-08-27","JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability","JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.","Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","2026-09-10","Unknown","https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384",{"date":90,"score":54,"percentile":98},0.17918,[100,103,106,109,112,115,118,121,124,127,130,133,136,139,142],{"date":101,"score":54,"percentile":102},"2026-08-13",0.1825,{"date":104,"score":54,"percentile":105},"2026-08-14",0.18261,{"date":107,"score":54,"percentile":108},"2026-08-15",0.1841,{"date":110,"score":54,"percentile":111},"2026-08-16",0.18432,{"date":113,"score":54,"percentile":114},"2026-08-17",0.1835,{"date":116,"score":54,"percentile":117},"2026-08-18",0.18365,{"date":119,"score":54,"percentile":120},"2026-08-19",0.18426,{"date":122,"score":54,"percentile":123},"2026-08-20",0.18453,{"date":125,"score":54,"percentile":126},"2026-08-21",0.18476,{"date":128,"score":54,"percentile":129},"2026-08-22",0.18485,{"date":131,"score":54,"percentile":132},"2026-08-23",0.18481,{"date":134,"score":54,"percentile":135},"2026-08-24",0.17837,{"date":137,"score":54,"percentile":138},"2026-08-25",0.17854,{"date":140,"score":54,"percentile":141},"2026-08-26",0.17919,{"date":90,"score":54,"percentile":98},[144,149],{"source":58,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":145,"cvss_v4_0":9},{"baseScore":56,"baseSeverity":146,"vectorString":59,"impactScore":147,"exploitabilityScore":148},"MEDIUM",6,4.1,{"source":64,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":150,"cvss_v4_0":9},{"baseScore":56,"baseSeverity":146,"vectorString":59,"impactScore":147,"exploitabilityScore":148},[152],{"ecosystem":9,"name":153,"vendor":154,"product":153,"cpe_part":155,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":156},"artifactory","jfrog","a",[157,162],{"version":158,"is_range":50,"range_type":159,"version_start":9,"version_start_type":9,"version_end":160,"version_end_type":161,"fixed_in":9},"lt7.146.35","cpe","7.146.35","excluding",{"version":163,"is_range":50,"range_type":159,"version_start":164,"version_start_type":165,"version_end":166,"version_end_type":161,"fixed_in":9},"gte7.161.0_lt7.161.16","7.161.0","including","7.161.16"]