HIGH 7.5 PyPI
Dagster vulnerable to Path Traversal attack through its /logs endpoint
GHSA-q93c-p2mw-p23f · CVE-2023-51232 · PYSEC-2026-1287
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').
Ready to move
Start Securing
Free, no credit card | First findings in minutes