Path Traversal Vulnerability in Shamefile by BKDDFS
CVE-2026-47144

5.5MEDIUM

Key Information:

Vendor

Bkddfs

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-47144?

Shamefile, a linter designed for undocumented linter warnings, contains a path traversal vulnerability in the 'shame next' command prior to version 0.1.7. This flaw allows attackers to exploit an attacker-controlled 'shamefile.yaml', potentially disclosing sensitive files located outside of the repository to the user running the command. The contents can be revealed line by line in the terminal. Users are advised to upgrade to version 0.1.7 or newer to mitigate this issue. As a precaution, do not execute 'shame next' on untrusted 'shamefile.yaml' files and utilize 'shame me --dry-run' for continuous integration validation.

Affected Version(s)

shamefile < 0.1.7

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.