Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jf4-fcjr-68c2

Опубликовано: 19 июн. 2025
Источник: github
Github: Прошло ревью
CVSS4: 2
CVSS3: 5.5

Описание

Upsonic is vulnerable to Path Traversal attack through its os.path.join function

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of the argument file.filename leads to path traversal. The exploit has been disclosed to the public and may be used.

Пакеты

Наименование

upsonic

pip
Затронутые версииВерсия исправления

< 0.56.0

0.56.0

EPSS

Процентиль: 32%
0.00122
Низкий

2 Low

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
nvd
8 месяцев назад

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of the argument file.filename leads to path traversal. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 32%
0.00122
Низкий

2 Low

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-22