Intel

AIKIDO-2024-10060

streamlit is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 26, 2024

40

Medium Risk

This Affects:

pythonstreamlit
1.11.1 - 1.29.0
Fixed in 1.30.0
Are you affected? Scan for Free

TL;DR

The affected versions of this package are susceptible to directory traversal due to inadequate validation of user-supplied input within custom components. By manipulating the input, an attacker can exploit this vulnerability to access sensitive files on the server by traversing directories.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

streamlit is vulnerable to Path Traversal in versions 1.11.1 - 1.29.0.

How to fix this

Upgrade the streamlit library to the patch version.