{"id":"CVE-2026-108258","summary":"Shiny for Python - Path traversal in bookmark restore","details":"Shiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shiny_bookmarks directory without validating that it is a single safe path segment. An unauthenticated request can use parent-directory segments or an absolute path to make the server open input.json and values.json outside the bookmark store, even when bookmark_store is set to disable. In applications configured with bookmark_store set to server and using ui.input_file(), the restore handler can additionally copy and expose an attacker-selected file from an attacker-selected directory. This issue is fixed in version 1.6.4.","aliases":["GHSA-47c3-hpmg-7j6p"],"modified":"2026-10-10T10:45:43.488571455Z","published":"2026-10-09T20:34:39.539Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108258.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108258.json"},{"type":"FIX","url":"https://github.com/posit-dev/py-shiny/commit/1d8ecb46cbc9621b7dc8812111d26692e086b376"},{"type":"WEB","url":"https://github.com/posit-dev/py-shiny/releases/tag/v1.6.4"},{"type":"ADVISORY","url":"https://github.com/posit-dev/py-shiny/security/advisories/GHSA-47c3-hpmg-7j6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-108258"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/posit-dev/py-shiny","events":[{"introduced":"571509177f10c18158e082db8e04a627d5d53b31"},{"fixed":"31ea9129296267d5df17638b3ffcec9635048c82"}],"database_specific":{"extracted_events":[{"introduced":"1.4.0"},{"fixed":"1.6.4"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108258.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}