PT-2026-109313 · Posit · Shiny For Python
CVE-2026-108258
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Shiny for Python versions 1.4.0 through 1.6.3
Description
The bookmark restore process accepts a client-supplied
state id query-string value and joins it into the server-side bookmark directory without proper validation. An unauthenticated request can use absolute paths or parent-directory segments (path traversal) to force the server to open and parse input.json and values.json from directories outside the intended bookmark store. This occurs even if the bookmark store is set to disable. In applications where bookmark store is set to server and ui.input file() is used, the restore handler can copy and expose the contents of an attacker-selected file from an attacker-selected directory.Recommendations
Update Shiny for Python to version 1.6.4.
As a temporary mitigation, strip the
state id parameter from incoming query strings at a reverse proxy or load balancer.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shiny For Python