Vulnerability GHSA-mpmf-hr8p-p49g
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
May 17, 2022 at 12:19 AM UTC
Sanic arbitrary file read and directory traversal
0.1.0 - 0.5.0
0.1.0 - 0.5.0
Summary
Sanic arbitrary file read and directory traversal
Details
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
14 days ago
sanic chunked trailer request smuggling allows hidden second request execution
0.1.0 - 24.12.0 and 25.12.0 GHSA-wmj6-g64g-j7q5
0.1.0 - 24.12.0 and 25.12.0 GHSA-wmj6-g64g-j7q5
High Risk
2 months ago
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 PYSEC-2026-918
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 PYSEC-2026-918
High Risk
4 years ago
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 GHSA-8cw9-5hmv-77w6
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 GHSA-8cw9-5hmv-77w6
High Risk
4 years ago
Server crash if running Python 3.10 w/ Sanic 20.12
0.1.7 - 20.12.5 GHSA-7p79-6x2v-5h88
0.1.7 - 20.12.5 GHSA-7p79-6x2v-5h88
Unknown
8 years ago
No summary available
0.1.0 - 0.5.0 PYSEC-2017-40
0.1.0 - 0.5.0 PYSEC-2017-40
Impacted packages
Timeline
Published
4 years ago
May 17, 2022 at 12:19 AM UTC
Fixed (0.5.1)
9 years ago
April 14, 2017 at 07:04 PM UTC
Last Modified
1 year ago
October 25, 2024 at 08:25 PM UTC