CRITICAL 9.3 PyPI

Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafely

GHSA-qp72-96p2-g644 · CVE-2022-31558 · PYSEC-2026-541

Published · Modified

Description

The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Ready to move

Start Securing

Free, no credit card | First findings in minutes