Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-47c3-hpmg-7j6p | Shiny for Python has path traversal in bookmark restore |
Fri, 09 Oct 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shiny_bookmarks directory without validating that it is a single safe path segment. An unauthenticated request can use parent-directory segments or an absolute path to make the server open input.json and values.json outside the bookmark store, even when bookmark_store is set to disable. In applications configured with bookmark_store set to server and using ui.input_file(), the restore handler can additionally copy and expose an attacker-selected file from an attacker-selected directory. This issue is fixed in version 1.6.4. | |
| Title | Shiny for Python - Path traversal in bookmark restore | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T20:34:39.539Z
Reserved: 2026-10-09T17:33:15.409Z
Link: CVE-2026-108258
No data.
Status : Received
Published: 2026-10-09T21:17:03.853
Modified: 2026-10-09T21:17:03.853
Link: CVE-2026-108258
No data.
OpenCVE Enrichment
Updated: 2026-10-09T21:30:12Z
Github GHSA