Intel

AIKIDO-2025-10252

pywb is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 18, 2025

91

Critical Risk

This Affects:

pythonpywb
0.0.1 - 2.8.3
Fixed in 2.8.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to path traversal due to a flaw in the static_handler, which allows attackers to access files outside the designated static directory.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pywb is vulnerable to Path Traversal in versions 0.0.1 - 2.8.3.

How to fix this

Upgrade the pywb library to the patch version.