Directory Traversal Vulnerability in Shiny for Python by Posit
CVE-2026-108258

6.9MEDIUM

Key Information:

Vendor

Posit-dev

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108258?

A directory traversal issue was identified in Shiny for Python, where the bookmark restore mechanism lacks proper validation of the client-supplied state_id. This vulnerability allows unauthenticated attackers to exploit the application by manipulating the path, potentially gaining access to sensitive files like input.json and values.json outside the designated bookmark store. This exposure occurs even when security settings are configured to restrict access, thereby posing a significant risk to the confidentiality and integrity of the data handled by such applications. The vulnerability has been resolved in version 1.6.4.

Affected Version(s)

py-shiny >= 1.4.0, < 1.6.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.