{"id":"CVE-2023-40274","aliases":["GHSA-xvv9-5j67-3rpq"],"url":"https://o3.security/vulnerability/CVE-2023-40274","summary":"zola Path Traversal vulnerability","details":"An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the \"zola serve\" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.","published":"2023-08-14T00:00:00Z","modified":"2026-07-15T01:49:05.336339219Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"crates.io","name":"zola","fixedVersion":null}],"fix":{"url":"https://github.com/getzola/zola/pull/2258","label":"getzola/zola#2258"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40274.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40274"},{"type":"REPORT","url":"https://github.com/getzola/zola/issues/2257"},{"type":"FIX","url":"https://github.com/getzola/zola/pull/2258"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:05.336339219Z"}}