GHSA-694v-63fq-fmr4

Suggest an improvement
Source
https://github.com/advisories/GHSA-694v-63fq-fmr4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-694v-63fq-fmr4/GHSA-694v-63fq-fmr4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-694v-63fq-fmr4
Aliases
Published
2022-05-04T00:00:24Z
Modified
2026-07-06T08:11:31Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Path Traversal in scout-browser
Details

Scout is a Variant Call Format (VCF) visualization interface. The Pypi package scout-browser is vulnerable to path traversal due to send_file call in versions prior to 4.52.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-36"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-05-18T19:57:37Z",
    "nvd_published_at": "2022-05-03T09:15:00Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / scout-browser

Package

Name
scout-browser
View open source insights on deps.dev
Purl
pkg:pypi/scout-browser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.52

Affected versions

1.*
1.2.0b1
1.2.0b2
1.2.0
1.4.0
2.*
2.0.0
3.*
3.0.2
3.0.3
3.0.5
3.0.6
3.0.7
3.3.1
3.5.0
4.*
4.0.0
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.2.1
4.2.2
4.3.0
4.3.1
4.4.1
4.7
4.7.2
4.7.3
4.8.0
4.8.2
4.8.3
4.9.0
4.10.1
4.11
4.12.3
4.12.4
4.13.1
4.14
4.14.1
4.15
4.15.1
4.16.1
4.18
4.21
4.21.1
4.21.2
4.22
4.23
4.24
4.24.1
4.25
4.26
4.26.1
4.27
4.28
4.29
4.29.1
4.30
4.30.1
4.30.2
4.31
4.31.1
4.32
4.32.1
4.33
4.33.1
4.34
4.35
4.36
4.37
4.38
4.39
4.40
4.40.1
4.41
4.42
4.42.1
4.43
4.43.1
4.44
4.45
4.46
4.46.1
4.47
4.48
4.48.1
4.49
4.50
4.50.1
4.51

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-694v-63fq-fmr4/GHSA-694v-63fq-fmr4.json"