{"id":"PYSEC-2026-745","summary":"Roundup Directory traversal vulnerability","details":"Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via `..` (dot dot) sequences in an `@@` command in an HTTP GET request.","aliases":["CVE-2004-1444","GHSA-q7mf-hp9m-cx6f"],"modified":"2026-07-06T08:00:51.696578875Z","published":"2026-07-02T14:13:18.630695Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1444"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16350"},{"type":"PACKAGE","url":"https://github.com/roundup-tracker/roundup"},{"type":"WEB","url":"http://packetstormsecurity.nl/0406-exploits/roundUP.txt"},{"type":"WEB","url":"http://secunia.com/advisories/11801"},{"type":"WEB","url":"http://securitytracker.com/id?1010415"},{"type":"WEB","url":"http://sourceforge.net/tracker/index.php?func=detail&aid=961511&group_id=31577&atid=402788"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml"},{"type":"WEB","url":"http://www.securityfocus.com/bid/10495"},{"type":"PACKAGE","url":"https://pypi.org/project/roundup"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q7mf-hp9m-cx6f"}],"affected":[{"package":{"name":"roundup","ecosystem":"PyPI","purl":"pkg:pypi/roundup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.3"}]}],"versions":["0.5.9","0.6.11","0.6.8","0.6.9","0.7.0","0.7.0b3","0.7.1","0.7.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/roundup/PYSEC-2026-745.yaml"}}],"schema_version":"1.7.5"}