{"id":"CVE-2022-31506","details":"The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.","aliases":["GHSA-x2pc-fqrw-hc7f","PYSEC-2026-436"],"modified":"2026-08-12T03:51:18.812207381Z","published":"2022-07-11T00:54:01Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31506.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31506.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31506"},{"type":"REPORT","url":"https://github.com/github/securitylab/issues/669#issuecomment-1117265726"},{"type":"FIX","url":"https://github.com/cmusatyalab/opendiamond/commit/398049c187ee644beabab44d6fece82251c1ea56"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cmusatyalab/opendiamond","events":[{"introduced":"0"},{"fixed":"398049c187ee644beabab44d6fece82251c1ea56"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:cmu:opendiamond:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"10.1.1"}]}}],"versions":["v10.1.1","v10.1.0","v10.0.2","v10.0.1","v10.0.0","v9.0.1","v9.0.0","v8.1.1","v8.1.0","v8.0.9","v8.0.8","v8.0.7","v8.0.6","v8.0.5","v8.0.4","v8.0.3","v8.0.2","v8.0.1","v8.0.0","v7.0.4","v7.0.3","v7.0.2","v7.0.1","v7.0.0","v6.2.0","v6.0.5","v6.0.4","v6.0.3","v6.0.2","v6.0.1","v6.0.0","v5.4.2","v5.4.1","v5.4.0","v5.3.1","v5.3.0","v5.2.1","v5.2.0","v5.1.2","v5.1.1","v5.1.0","v5.0.7","v5.0.6","v5.0.5","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v3.3.0","v3.2.3","v3.2.2","v3.2.1","v3.2.0","v3.1.1","v3.1.0","v3.0.2","v3.0.1","v3.0.0","opendiamond-2-1-0","opendiamond-2-0-1","opendiamond-2-0-0","diamond-1-3-2","pre_objcache","diamond-1-2-0","diamond-1-1-0","HPDC_Submit","USENIX05_SUBMIT","BEFORE_CACHE","RID_DEMO","SNAPFIND_SUBMIT_ACM_MM","fast04_submit_version","country_fair_july_2003","pre_country_fair_july_2003","rajiv-2003-july-07-working-01","rajiv-2003-july-01-working-02","rajiv-2003-july-01-working-01","before_move","demo-2003-03-13","Before_Adisk_Daemon"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-31506.json"}}],"schema_version":"1.9.0"}