CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration
Vulnerability ID: CVE-2026-108258
CVSS Score: 6.9
Published: 2026-10-09
A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted state_id query parameters.
TL;DR
Unsanitized query parameters in Shiny for Python's session bookmark feature allow unauthenticated path traversal and arbitrary file read.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22
- Attack Vector: Network (HTTP / WebSocket)
- CVSS v4.0 Score: 6.9 (Medium)
- Exploit Status: Proof of Concept / Public Patch
- CISA KEV Status: Not Listed
- Authentication Required: None (Unauthenticated)
Affected Systems
- Shiny for Python (PyPI package 'shiny') applications using session state bookmarking
-
shiny: >= 1.4.0, < 1.6.4 (Fixed in:
1.6.4)
Code Analysis
Commit: 1d8ecb4
Fix path traversal in bookmark state restoration
Exploit Details
- GitHub Security Advisory: Technical description and reproduction details in official repository advisory
Mitigation Strategies
- Upgrade Shiny for Python package to version 1.6.4 or later.
- Configure Web Application Firewall (WAF) rules to filter directory traversal sequences in URL query parameters.
- Disable server-side bookmark storage if session persistence is not required.
Remediation Steps:
- Execute 'pip install --upgrade shiny' in the application environment.
- Verify the installed version using 'python -c "import shiny; print(shiny.version)"' ensures version >= 1.6.4.
- Deploy WAF rules blocking HTTP GET parameters containing '_state_id=' with '..' or absolute paths.
References
- GitHub Security Advisory GHSA-47c3-hpmg-7j6p
- Official Patch Commit
- Shiny for Python Release v1.6.4
- NVD CVE-2026-108258 Detail
- CVE Record CVE-2026-108258
Read the full report for CVE-2026-108258 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)