The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
"https://github.com/pypa/advisory-database/blob/main/vulns/shiva/PYSEC-2026-541.yaml"