PYSEC-2026-1933

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/solara/PYSEC-2026-1933.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1933
Aliases
Published
2026-07-07T14:34:36Z
Modified
2026-07-07T17:47:08Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Local File Inclusion in Solara
Details

A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.

References

References

Affected packages

PyPI / solara

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.35.1

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.4.3a4
0.5.0a0
0.5.0
0.5.1
0.5.2
0.7.0
0.8.0
0.8.1
0.9.0
0.9.1
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.17.0
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
1.18.0
1.19.0
1.20.0
1.21.0
1.22.0
1.23.0
1.24.0
1.25.0
1.25.1
1.26.0
1.26.1
1.27.0
1.28.0
1.29.0
1.29.1
1.30.0
1.30.1
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.34.1
1.35.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/solara/PYSEC-2026-1933.yaml"