rich-rst is vulnerable to Path Traversal
75
High Risk
The .. literalinclude:: directive in rich-rst reads the file path given in its argument without checking that the path stays inside the source document's directory. Absolute paths and ../ parent directory segments both resolve, so rendering reStructuredText from an untrusted source discloses any file the rendering process can read, such as /etc/passwd. The fix disables directives that read other files by default and, when re-enabled through allow_file_access, resolves symlinks and rejects paths outside the source directory.
You are affected if you are using a version that falls within the vulnerable range and you render reStructuredText markup from an untrusted source.
rich-rst is vulnerable to Path Traversal in versions 0.0.1 - 2.1.0.
Upgrade the rich-rst library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.