StackRadar

CVE-2026-48049

Medium

Advisory

Published 11 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

@hapi/inert has a static-file confinement bypass via sibling-prefix path

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
@hapi/inertnpm5.2.2, 6.0.3, 6.0.4, 6.0.5+1 more7.1.118
OSV records
GHSA-rcvq-m9j9-6f4g

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
@hapi/inert@6.0.5
7.1.1

Open the chart page →

11,384
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
@hapi/inert@6.0.5
7.1.1

Open the chart page →

6,168
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
@hapi/inert@6.0.5
7.1.1

Open the chart page →

10,530
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
@hapi/inert@5.2.2
7.1.1

Open the chart page →

17,896
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
@hapi/inert@6.0.5
7.1.1

Open the chart page →

1,843
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
@hapi/inert@6.0.4
7.1.1

Open the chart page →

17,284
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
@hapi/inert@6.0.4
7.1.1

Open the chart page →

6,879
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
@hapi/inert@6.0.5
7.1.1

Open the chart page →

13,852
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
@hapi/inert@6.0.4
7.1.1

Open the chart page →

34,754
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/inert@6.0.4
7.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/inert@5.2.2
7.1.1

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/inert@6.0.4
7.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/inert@5.2.2
7.1.1

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/inert@6.0.4
7.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/inert@5.2.2
7.1.1

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@hapi/inert@7.1.0
7.1.1

Open the chart page →

2,457
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
@hapi/inert@7.1.0
7.1.1

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/inert@5.2.2
7.1.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/inert@6.0.3
7.1.1

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/inert@6.0.4
7.1.1
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/inert@6.0.4
7.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/inert@5.2.2
7.1.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/inert@6.0.3
7.1.1

Open the chart page →

19,226
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
@hapi/inert@7.1.0
7.1.1

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@hapi/inert@7.1.0
7.1.1

Open the chart page →

2,457
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
@hapi/inert@6.0.5
7.1.1

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
@hapi/inert@7.1.0
7.1.1

Open the chart page →

6,285
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-48049.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
@hapi/inert@6.0.5
7.1.1

Open the chart page →

9,381

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/inert@5.2.2
7.1.1
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/inert@6.0.4
7.1.1
3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/inert@6.0.4
7.1.1
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/inert@6.0.3
7.1.1
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
@hapi/inert@7.1.0
7.1.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@hapi/inert@7.1.0
7.1.1
2
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
@hapi/inert@5.2.2
7.1.1
1
library/kibana:7.17.150172f1c538e7
@hapi/inert@6.0.4
7.1.1
1
library/kibana:8.18.004c0fc150f3a
@hapi/inert@7.1.0
7.1.1
1
library/kibana:7.17.8c5781ba340ef
@hapi/inert@6.0.4
7.1.1
1
library/kibana:7.17.3e2e2031c15be
@hapi/inert@6.0.4
7.1.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
@hapi/inert@6.0.5
7.1.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
@hapi/inert@6.0.5
7.1.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
@hapi/inert@6.0.5
7.1.1
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
@hapi/inert@6.0.5
7.1.1
1
wazuh/wazuh-dashboard:4.4.11787550d2358
@hapi/inert@6.0.5
7.1.1
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
@hapi/inert@6.0.5
7.1.1
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
@hapi/inert@6.0.5
7.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.