The validation for the file URI scheme falls short, and results in an attacker being able to read any file on the system. This issue only affects instances with a webdriver enabled, and ALLOW_FILE_URI false or not defined.
The check used for URL protocol, is_safe_url, allows file: as a URL scheme:
It later checks if local files are permitted, but one of the preconditions for the check is that the URL starts with file://. The issue comes with the fact that the file URI scheme is not required to have double slashes.
A valid file URI must therefore begin with either
file:/path(no hostname),file:///path(empty hostname), orfile://hostname/path. — Wikipedia
file:/etc/passwd or a similar path for your operating system. Enable webdriver mode{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2024-11-07T22:00:58Z",
"nvd_published_at": "2024-11-08T00:15:15Z",
"severity": "HIGH"
}