{"id":"CVE-2023-40274","details":"An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the \"zola serve\" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.","aliases":["GHSA-xvv9-5j67-3rpq"],"modified":"2026-08-12T03:51:47.621774814Z","published":"2023-08-14T00:00:00Z","related":["CGA-g5ch-g69r-pc89"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40274.json","cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40274.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40274"},{"type":"REPORT","url":"https://github.com/getzola/zola/issues/2257"},{"type":"FIX","url":"https://github.com/getzola/zola/pull/2258"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getzola/zola","events":[{"introduced":"1ef8c85f53b4988fdafc0e6271cce590515d55aa"},{"fixed":"7c6bdc1019dbfa1c59667dd6ba0cacf30774b41b"}],"database_specific":{"source":["DESCRIPTION","CPE_RANGE"],"cpe":"cpe:2.3:a:getzola:zola:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.13.0"},{"fixed":"0.17.2"},{"last_affected":"0.17.2"}]}}],"versions":["v0.17.1","v0.17.0","v0.16.1","v0.16.0","v0.15.3","v0.15.1","v0.15.0","v0.14.1","v0.14.0","v0.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-40274.json"}}],"schema_version":"1.9.0"}