{"id":"CVE-2021-23423","aliases":["GHSA-hf6p-4rv2-9qrp","PYSEC-2021-117","SNYK-PYTHON-BIKESHED-1537647"],"url":"https://o3.security/vulnerability/CVE-2021-23423","summary":"Path Traversal in bikshed","details":"This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.","published":"2021-08-16T08:15:11.393Z","modified":"2026-07-08T06:29:50.513894321Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"bikeshed","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cb6b2dd","label":"tabatkins/bikeshed@b2f668f"},"references":[{"type":"FIX","url":"https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cb6b2dd"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537647"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:29:50.513894321Z"}}