Description
Shiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shiny_bookmarks directory without validating that it is a single safe path segment. An unauthenticated request can use parent-directory segments or an absolute path to make the server open input.json and values.json outside the bookmark store, even when bookmark_store is set to disable. In applications configured with bookmark_store set to server and using ui.input_file(), the restore handler can additionally copy and expose an attacker-selected file from an attacker-selected directory. This issue is fixed in version 1.6.4.
Published: 2026-10-09
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: File System Access
Action: Patch Now
AI Analysis

Impact

Shiny for Python includes a path traversal flaw in its bookmark restore feature, allowing an attacker to supply a malicious state_id that is joined into the server‑side bookmark directory without proper sanitization. An unauthenticated user can therefore cause the application to open input.json and values.json located outside the intended bookmark store, or even copy a chosen file from an arbitrary directory when bookmark_store is enabled and ui.input_file is used. This vulnerability could lead to unauthorized file disclosure or execution and compromise the integrity of the deployed application.

Affected Systems

Shiny for Python (py‑shiny) versions 1.4.0 through 1.6.3 (any release before the 1.6.4 fix) on all platforms supported by the framework.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only an unauthenticated request to the bookmark restore endpoint, making the attack vector low effort for anyone able to craft a state_id that includes parent‑directory escapes or an absolute path. Because the flaw is present in a widely used framework, the potential impact is significant if the application hosts sensitive data or serves a broad user base.

Generated by OpenCVE AI on October 9, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Shiny for Python to version 1.6.4 or later to apply the vendor fix.
  • If an upgrade is not immediately possible, disable bookmark restore functionality or remove usage of ui.input_file to eliminate the file‑exposure path.
  • Implement server‑side validation to ensure that any supplied state_id is a single, safe path segment, providing a temporary safeguard until a patch can be applied.

Generated by OpenCVE AI on October 9, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-47c3-hpmg-7j6p Shiny for Python has path traversal in bookmark restore
History

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description Shiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shiny_bookmarks directory without validating that it is a single safe path segment. An unauthenticated request can use parent-directory segments or an absolute path to make the server open input.json and values.json outside the bookmark store, even when bookmark_store is set to disable. In applications configured with bookmark_store set to server and using ui.input_file(), the restore handler can additionally copy and expose an attacker-selected file from an attacker-selected directory. This issue is fixed in version 1.6.4.
Title Shiny for Python - Path traversal in bookmark restore
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:34:39.539Z

Reserved: 2026-10-09T17:33:15.409Z

Link: CVE-2026-108258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:03.853

Modified: 2026-10-09T21:17:03.853

Link: CVE-2026-108258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:30:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')