Directory Traversal Vulnerability in Shiny for Python by Posit
CVE-2026-108258
6.9MEDIUM
What is CVE-2026-108258?
A directory traversal issue was identified in Shiny for Python, where the bookmark restore mechanism lacks proper validation of the client-supplied state_id. This vulnerability allows unauthenticated attackers to exploit the application by manipulating the path, potentially gaining access to sensitive files like input.json and values.json outside the designated bookmark store. This exposure occurs even when security settings are configured to restrict access, thereby posing a significant risk to the confidentiality and integrity of the data handled by such applications. The vulnerability has been resolved in version 1.6.4.
Affected Version(s)
py-shiny >= 1.4.0, < 1.6.4
