dagster is vulnerable to Local File Inclusion (LFI)
68
Medium Risk
Affected versions of this package are vulnerable to local file inclusion (LFI) due to insufficient path validation in the ExternalNotebookData gRPC endpoint. The get_notebook_data function only checks if the file path ends with .ipynb, allowing attackers to use path traversal sequences (e.g., ../) to access arbitrary files. Although the server binds to localhost by default, custom or cloud deployments exposed to external networks may be at risk of unauthorized file access.
You are affected if you are using a version that falls within the vulnerable range and your server does not bind to localhost.
dagster is vulnerable to Local File Inclusion (LFI) in versions 0.12.8 - 1.10.15.
Upgrade the dagster library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant