rich-rst is vulnerable to Path Traversal
75
High Risk
The .. raw:: and .. csv-table:: directives' :file: and :url: options, along with the docutils include directive, read the referenced file or fetch the referenced URL with no restriction and include the contents in the output. Rendering reStructuredText from an untrusted source discloses any file the rendering process can read or triggers outbound requests to URLs supplied in that markup. The fix disables these directives by default and confines re-enabled access to the source document's directory.
You are affected if you are using a version that falls within the vulnerable range and you render reStructuredText markup from an untrusted source.
rich-rst is vulnerable to Path Traversal in versions 0.0.1 - 2.1.0.
Upgrade the rich-rst library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.