Path Concatenation Vulnerability in pygeoapi by Geopython
CVE-2026-42351
7.5HIGH
What is CVE-2026-42351?
The pygeoapi implementation has a vulnerability in the STAC FileSystemProvider plugin, allowing unprotected access to directory resources. This occurs due to improper handling of raw string path concatenation when deployed without a proper URL normalizing proxy. If exploited, it can result in unauthorized exposure of sensitive directories within STAC collections. Users are encouraged to upgrade to version 0.23.3 or later to mitigate this risk.
Affected Version(s)
pygeoapi >= 0.23.0, < 0.23.3
