{"id":"GHSA-q7mf-hp9m-cx6f","summary":"Roundup Directory traversal vulnerability","details":"Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via `..` (dot dot) sequences in an `@@` command in an HTTP GET request.","aliases":["CVE-2004-1444","PYSEC-2026-745"],"modified":"2026-07-06T08:11:28.382205370Z","published":"2022-04-29T02:59:35Z","database_specific":{"nvd_published_at":"2004-12-31T05:00:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-09T16:05:51Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1444"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16350"},{"type":"PACKAGE","url":"https://github.com/roundup-tracker/roundup"},{"type":"WEB","url":"http://packetstormsecurity.nl/0406-exploits/roundUP.txt"},{"type":"WEB","url":"http://secunia.com/advisories/11801"},{"type":"WEB","url":"http://securitytracker.com/id?1010415"},{"type":"WEB","url":"http://sourceforge.net/tracker/index.php?func=detail&aid=961511&group_id=31577&atid=402788"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml"},{"type":"WEB","url":"http://www.securityfocus.com/bid/10495"}],"affected":[{"package":{"name":"roundup","ecosystem":"PyPI","purl":"pkg:pypi/roundup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.3"}]}],"versions":["0.5.9","0.6.11","0.6.8","0.6.9","0.7.0","0.7.0b3","0.7.1","0.7.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-q7mf-hp9m-cx6f/GHSA-q7mf-hp9m-cx6f.json"}}],"schema_version":"1.9.0"}