allure-commandline is vulnerable to Path Traversal
50
Medium Risk
The local report preview server started by allure serve and allure open maps request paths into the report directory and checks containment with a lexical prefix comparison. It applies no-follow-symlink handling only to the final path component, so an intermediate directory component that is a symlink is resolved and followed during path resolution. This lets someone who can influence the served report directory read arbitrary files accessible to the Allure process. The fix resolves canonical real paths before enforcing containment.
You are affected if you are using a version that falls within the vulnerable range and you use allure serve or allure open to preview a report whose directory contents can be influenced by untrusted test results.
allure-commandline is vulnerable to Path Traversal in versions 0.0.1 - 2.44.1.
Upgrade the allure-commandline and/or the io.qameta.allure:allure-commandline library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant