HIGH 7.5 PyPI
Sanic arbitrary file read and directory traversal
GHSA-mpmf-hr8p-p49g · CVE-2017-16762 · PYSEC-2017-40
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2017-16762
- WEB https://github.com/channelcat/sanic/issues/633
- WEB https://github.com/sanic-org/sanic/pull/635
- WEB https://github.com/channelcat/sanic/releases/tag/0.5.1
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/sanic/PYSEC-2017-40.yaml
- PACKAGE https://github.com/sanic-org/sanic
Ready to move
Start Securing
Free, no credit card | First findings in minutes