CVE-2026-49846: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in signalwire libks
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.
AI Analysis
Technical Summary
The vulnerability in libks's clean_uri() function occurs because it does not properly handle URIs whose path segments exceed the size of its canonicalization buffer. As a result, the function silently allows URIs containing ".." sequences to pass through unfiltered. When these URIs are later combined with filesystem paths by consumers of libks, it can lead to path traversal attacks. This flaw affects all versions of libks before 2.0.11, which includes the vulnerable code. The issue is fixed in version 2.0.11.
Potential Impact
An attacker can exploit this vulnerability to perform path traversal attacks by crafting specially formed URIs that bypass the canonicalization step. This can lead to unauthorized access to files outside the intended directory scope. The CVSS score of 7.5 (high) reflects the network attack vector, low attack complexity, no privileges or user interaction required, and high confidentiality impact. There is no impact on integrity or availability reported.
Mitigation Recommendations
Upgrade libks to version 2.0.11 or later, where the vulnerability is patched. No other mitigation is necessary as the fix is official and addresses the root cause.
CVE-2026-49846: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in signalwire libks
Description
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.
CVSS v3.1
Score 7.5high
Affected software
signalwire
libks
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in libks's clean_uri() function occurs because it does not properly handle URIs whose path segments exceed the size of its canonicalization buffer. As a result, the function silently allows URIs containing ".." sequences to pass through unfiltered. When these URIs are later combined with filesystem paths by consumers of libks, it can lead to path traversal attacks. This flaw affects all versions of libks before 2.0.11, which includes the vulnerable code. The issue is fixed in version 2.0.11.
Potential Impact
An attacker can exploit this vulnerability to perform path traversal attacks by crafting specially formed URIs that bypass the canonicalization step. This can lead to unauthorized access to files outside the intended directory scope. The CVSS score of 7.5 (high) reflects the network attack vector, low attack complexity, no privileges or user interaction required, and high confidentiality impact. There is no impact on integrity or availability reported.
Mitigation Recommendations
Upgrade libks to version 2.0.11 or later, where the vulnerability is patched. No other mitigation is necessary as the fix is official and addresses the root cause.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-01T22:03:19.640Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa4737691cc7f3848ae20c1
Added to database: 09/11/2026, 21:32:38 UTC
Last enriched: 09/11/2026, 21:47:15 UTC
Last updated: 09/11/2026, 22:23:22 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.