Vulnerability PYSEC-2026-2045

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
July 07, 2026 at 02:34 PM UTC
Werkzeug safe_join not safe on Windows
0.1 - 3.0.5
0.1 - 3.0.5

Summary

Werkzeug safe_join not safe on Windows

Details

On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable.

Impacted packages

Timeline

Published
3 months ago
July 07, 2026 at 02:34 PM UTC
Fixed (3.0.6)
1 year ago
October 25, 2024 at 06:52 PM UTC
Last Modified
3 months ago
July 07, 2026 at 05:47 PM UTC