Intel

AIKIDO-2026-826619

rich-rst is vulnerable to Path Traversal

Path TraversalGHSA-qx2q-xxw7-587f Published 2 days ago

75

High Risk

This Affects:

PYTHONrich-rst
0.0.1 - 2.1.0
Fixed in 2.2.0
Are you affected? Scan for Free

TL;DR

The .. raw:: and .. csv-table:: directives' :file: and :url: options, along with the docutils include directive, read the referenced file or fetch the referenced URL with no restriction and include the contents in the output. Rendering reStructuredText from an untrusted source discloses any file the rendering process can read or triggers outbound requests to URLs supplied in that markup. The fix disables these directives by default and confines re-enabled access to the source document's directory.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you render reStructuredText markup from an untrusted source.

Background info

rich-rst is vulnerable to Path Traversal in versions 0.0.1 - 2.1.0.

How to fix this

Upgrade the rich-rst library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform