banks is vulnerable to Path Traversal
75
High Risk
The image, audio, video, and document filters pass user controlled template values straight into the from_path methods on ImageUrl, InputAudio, InputVideo, and InputDocument, which call open() on the supplied path without resolving or restricting it. A template variable holding a traversal sequence or absolute path such as ../../../etc/passwd causes that file to be read, base64 encoded, and embedded in the rendered output where it can be exfiltrated, exposing any file readable by the running process. The fix passes every path through a resolver that rejects locations outside the allowed media root.
You are affected if you are using a version that falls within the vulnerable range and you pass untrusted data into the image, audio, video, or document filters as a file path.
banks is vulnerable to Path Traversal in versions 1.5.0 - 2.4.3.
Upgrade the banks library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.