Path Traversal Vulnerability in Emmett Framework Affecting Multiple Versions
CVE-2026-39847

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39847?

The Emmett Framework, a full-stack Python web framework, is susceptible to path traversal attacks due to a flaw in the RSGI static handler responsible for internal assets. Attackers can exploit this vulnerability by manipulating the URL to traverse the filesystem, potentially gaining access to sensitive files beyond the intended directory. This issue has been addressed in version 2.8.1, and users are advised to upgrade to ensure application security and safeguard against unauthorized file access.

Affected Version(s)

emmett >= 2.5.0, < 2.8.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.