{"id":"CVE-2024-39903","aliases":["GHSA-9794-pc4r-438w","PYSEC-2026-1933"],"url":"https://o3.security/vulnerability/CVE-2024-39903","summary":"Local File Inclusion in Solara","details":"Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.","published":"2024-07-12T14:28:15.073Z","modified":"2026-07-15T01:49:15.470694972Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"solara","fixedVersion":"1.35.1"}],"fix":{"url":"https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54","label":"widgetti/solara@df2fd66"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39903.json"},{"type":"ADVISORY","url":"https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39903"},{"type":"FIX","url":"https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:15.470694972Z"}}