HIGH 7.5 PyPI

Dagster vulnerable to Path Traversal attack through its /logs endpoint

GHSA-q93c-p2mw-p23f · CVE-2023-51232 · PYSEC-2026-1287

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').

Ready to move

Start Securing

Free, no credit card | First findings in minutes