{"id":"CVE-2021-41185","details":"Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a workaround, users may manually apply the changes from the fix commit.","aliases":["GHSA-252r-94ph-m229"],"modified":"2026-07-09T10:01:06.395577Z","published":"2021-10-26T15:15:10.533Z","references":[{"type":"ADVISORY","url":"https://github.com/kizniche/Mycodo/releases/tag/v8.12.7"},{"type":"REPORT","url":"https://github.com/kizniche/Mycodo/issues/1105"},{"type":"FIX","url":"https://github.com/kizniche/Mycodo/commit/23ac5dd422029c2b6ae1701a3599b6d41b66a6a9"},{"type":"FIX","url":"https://github.com/kizniche/Mycodo/security/advisories/GHSA-252r-94ph-m229"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kizniche/mycodo","events":[{"introduced":"0"},{"fixed":"71a08b9955fecb8b5984a3ab9dc63c71d58eaa5b"},{"fixed":"23ac5dd422029c2b6ae1701a3599b6d41b66a6a9"}],"database_specific":{"cpe":"cpe:2.3:a:mycodo_project:mycodo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.12.7"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v8.12.6","v8.12.5","v8.12.4","v8.12.3","v8.12.2","v8.12.1","v8.12.0","v8.11.0","v8.10.1","v8.10.0","v8.9.2","v8.9.1","v8.9.0","v8.8.8","v8.8.7","v8.8.6","v8.8.5","v8.8.4","v8.8.3","v8.8.2","v8.8.1","v8.8.0","v8.7.2","v8.7.1","v8.7.0","v8.6.4","v8.6.3","v8.6.2","v8.6.1","v8.6.0","v8.5.8","v8.5.7","v8.5.6","v8.5.5","v8.5.2","v8.5.1","v8.5.0","v8.4.0","v8.3.0","v8.2.5","v8.2.4","v8.2.3","v8.2.2","v8.2.1","v8.1.1","v8.1.0","v8.0.3","v8.0.2","v8.0.1","v8.0.0","v7.10.0","v7.9.1","v7.9.0","v7.8.4","v7.8.3","v7.8.2","v7.8.1","v7.8.0","v7.7.9","v7.7.8","v7.7.7","v7.7.6","v7.7.5","v7.7.4","v7.7.3","v7.7.2","v7.7.1","v7.7.0","v7.6.3","v7.6.2","v7.6.1","v7.6.0","v7.5.10","v7.5.9","v7.5.8","v7.5.7","v7.5.6","v7.5.5","v7.5.4","v7.5.3","v7.5.2","v7.5.1","v7.5.0","v7.4.3","v7.4.2","v7.4.1","v7.4.0","v7.3.1","v7.3.0","v7.2.4","v7.2.3","v7.2.2","v7.2.1","v7.2.0","v7.1.7","v7.1.6","v7.1.5","v7.1.4","v7.1.3","v7.1.2","v7.1.1","v7.1.0","v7.0.5","v7.0.4","v7.0.3","v7.0.2","v7.0.1","v7.0.0","v6.4.7","v6.4.5","v6.4.4","v6.4.3","v6.4.2","v6.4.1","v6.4.0","v6.3.9","v6.3.8","v6.3.7","v6.3.6","v6.3.5","v6.3.4","v6.3.3","v6.3.2","v6.3.1","v6.2.4","v6.2.3","v6.2.2","v6.2.1","v6.2.0","v6.1.4","v6.1.3","v6.1.2","v6.1.1","v6.1.0","v6.0.9","v6.0.8","v6.0.7","v6.0.6","v6.0.5","v6.0.4","v6.0.3","v6.0.2","v6.0.1","v6.0.0","v5.7.3","v5.7.2","v5.7.1","v5.7.0","v5.6.10","v5.6.9","v5.6.8","v5.6.7","v5.6.6","v5.6.5","v5.6.4","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v5.5.24","v5.5.23","v5.5.22","v5.5.21","v5.5.20","v5.5.19","v5.5.18","v5.5.17","v5.5.16","v5.5.15","v5.5.14","v5.5.13","v5.5.12","v5.5.11","v5.5.10","v5.5.9","v5.5.8","v5.5.6","v5.5.7","v5.5.5","v5.5.4","v5.5.3","v5.5.2","v5.5.1","v5.5.0","v5.4.19","v5.4.18","v5.4.17","v5.4.16","v5.4.15","v5.4.14","v5.4.11","v5.4.10","v5.4.9","v5.4.8","v5.4.7","v5.4.6","v5.4.5","v5.4.4","v5.4.3","v5.4.2","v5.3.6","v5.3.5","v5.3.4","v5.3.3","v5.3.2","v5.3.1","v5.3.0","v5.2.5","v5.2.4","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.1.10","v5.1.9","v5.1.8","v5.1.7","v5.1.6","v5.1.5","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.49","v5.0.48","v5.0.47","v5.0.45","v5.0.44","v5.0.43","v5.0.42","v5.0.41","v5.0.40","v5.0.39","v5.0.38","v5.0.36","v5.0.35","v5.0.34","v5.0.33","v5.0.32","v5.0.31","v5.0.30","v5.0.29","v5.0.28","v5.0.27","v5.0.26","v5.0.25","v5.0.24","v5.0.23","v5.0.22","v5.0.21","v5.0.20","v5.0.19","v5.0.18","v5.0.17","v5.0.16","v5.0.15","v5.0.14","v5.0.13","v5.0.12","v5.0.11","v5.0.10","v5.0.9","v5.0.8","v5.0.7","v5.0.6","v5.0.5","v5.0.4","v5.0.0","v4.1.16","v4.1.15","v4.1.14","v4.1.13","v4.1.12","v4.1.11","v4.1.10","v4.1.9","v4.1.8","v4.1.7","v4.1.6","v4.1.5","v4.1.4","v4.0.26"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41185.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}