PT-2026-109313 · Posit · Shiny For Python

CVE-2026-108258

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Shiny for Python versions 1.4.0 through 1.6.3
Description The bookmark restore process accepts a client-supplied state id query-string value and joins it into the server-side bookmark directory without proper validation. An unauthenticated request can use absolute paths or parent-directory segments (path traversal) to force the server to open and parse input.json and values.json from directories outside the intended bookmark store. This occurs even if the bookmark store is set to disable. In applications where bookmark store is set to server and ui.input file() is used, the restore handler can copy and expose the contents of an attacker-selected file from an attacker-selected directory.
Recommendations Update Shiny for Python to version 1.6.4. As a temporary mitigation, strip the state id parameter from incoming query strings at a reverse proxy or load balancer.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108258
GHSA-47C3-HPMG-7J6P

Affected Products

Shiny For Python