{"id":"CVE-2023-51232","aliases":["PYSEC-2026-1287"],"url":"https://o3.security/vulnerability/CVE-2023-51232","summary":"Dagster vulnerable to Path Traversal attack through its /logs endpoint","details":"Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').","published":"2025-07-07T15:30:38Z","modified":"2026-07-07T17:57:06.251157938Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dagster","fixedVersion":"1.5.11"}],"fix":{"url":"https://github.com/dagster-io/dagster/pull/18462","label":"dagster-io/dagster#18462"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-51232"},{"type":"WEB","url":"https://github.com/dagster-io/dagster/pull/18462"},{"type":"WEB","url":"https://github.com/dagster-io/dagster/commit/dbb064c2ddda74265b8174edd9775e1302ca6ba0"},{"type":"PACKAGE","url":"https://github.com/dagster-io/dagster"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:06.251157938Z"}}