Path Traversal Vulnerability in Emmett Framework Affecting Multiple Versions
CVE-2026-39847
9.1CRITICAL
What is CVE-2026-39847?
The Emmett Framework, a full-stack Python web framework, is susceptible to path traversal attacks due to a flaw in the RSGI static handler responsible for internal assets. Attackers can exploit this vulnerability by manipulating the URL to traverse the filesystem, potentially gaining access to sensitive files beyond the intended directory. This issue has been addressed in version 2.8.1, and users are advised to upgrade to ensure application security and safeguard against unauthorized file access.
Affected Version(s)
emmett >= 2.5.0, < 2.8.1
