Impact
Shiny for Python includes a path traversal flaw in its bookmark restore feature, allowing an attacker to supply a malicious state_id that is joined into the server‑side bookmark directory without proper sanitization. An unauthenticated user can therefore cause the application to open input.json and values.json located outside the intended bookmark store, or even copy a chosen file from an arbitrary directory when bookmark_store is enabled and ui.input_file is used. This vulnerability could lead to unauthorized file disclosure or execution and compromise the integrity of the deployed application.
Affected Systems
Shiny for Python (py‑shiny) versions 1.4.0 through 1.6.3 (any release before the 1.6.4 fix) on all platforms supported by the framework.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only an unauthenticated request to the bookmark restore endpoint, making the attack vector low effort for anyone able to craft a state_id that includes parent‑directory escapes or an absolute path. Because the flaw is present in a widely used framework, the potential impact is significant if the application hosts sensitive data or serves a broad user base.
OpenCVE Enrichment
Github GHSA