Arbitrary File Read Vulnerability in Allure Report by Allure Framework
CVE-2026-33166
8.6HIGH
What is CVE-2026-33166?
A vulnerability has been identified in the Allure Report prior to version 2.38.0, which allows an attacker to perform arbitrary file read operations. By crafting malicious result files such as -result.json or -container.json, an attacker can exploit path traversal mechanisms and point to sensitive files on the host system. When the Allure report generator processes these files during report generation, it inadvertently includes sensitive data in the generated reports. This poses a significant risk, particularly in environments where sensitive information is stored on the same machine. Users are advised to update to version 2.38.0 or later to mitigate this risk.
Affected Version(s)
allure2 < 2.38.0
