MEDIUM 6.6 PyPI
Dagster Local File Inclusion vulnerability
GHSA-h7x8-jv97-fvvm · CVE-2025-51481 · PYSEC-2025-102
Published · Modified
Description
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-51481
- WEB https://github.com/dagster-io/dagster/pull/30002
- WEB https://github.com/dagster-io/dagster/commit/3a3cec2b51577c4970e6fc4c199cda6418c09a9d
- PACKAGE https://github.com/dagster-io/dagster
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/dagster-ge/PYSEC-2025-102.yaml
- WEB https://www.gecko.security/blog/cve-2025-51481
Ready to move
Start Securing
Free, no credit card | First findings in minutes