SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely
Details
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. A patch is available on the master branch of the repository.