Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.
"https://github.com/pypa/advisory-database/blob/main/vulns/cherrypy/PYSEC-2006-1.yaml"