Arbitrary File Read Vulnerability in Allure Report by Allure Framework
CVE-2026-33166

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33166?

A vulnerability has been identified in the Allure Report prior to version 2.38.0, which allows an attacker to perform arbitrary file read operations. By crafting malicious result files such as -result.json or -container.json, an attacker can exploit path traversal mechanisms and point to sensitive files on the host system. When the Allure report generator processes these files during report generation, it inadvertently includes sensitive data in the generated reports. This poses a significant risk, particularly in environments where sensitive information is stored on the same machine. Users are advised to update to version 2.38.0 or later to mitigate this risk.

Affected Version(s)

allure2 < 2.38.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.