DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-108258: CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration

CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration

Vulnerability ID: CVE-2026-108258
CVSS Score: 6.9
Published: 2026-10-09

A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted state_id query parameters.

TL;DR

Unsanitized query parameters in Shiny for Python's session bookmark feature allow unauthenticated path traversal and arbitrary file read.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22
  • Attack Vector: Network (HTTP / WebSocket)
  • CVSS v4.0 Score: 6.9 (Medium)
  • Exploit Status: Proof of Concept / Public Patch
  • CISA KEV Status: Not Listed
  • Authentication Required: None (Unauthenticated)

Affected Systems

  • Shiny for Python (PyPI package 'shiny') applications using session state bookmarking
  • shiny: >= 1.4.0, < 1.6.4 (Fixed in: 1.6.4)

Code Analysis

Commit: 1d8ecb4

Fix path traversal in bookmark state restoration

Exploit Details

Mitigation Strategies

  • Upgrade Shiny for Python package to version 1.6.4 or later.
  • Configure Web Application Firewall (WAF) rules to filter directory traversal sequences in URL query parameters.
  • Disable server-side bookmark storage if session persistence is not required.

Remediation Steps:

  1. Execute 'pip install --upgrade shiny' in the application environment.
  2. Verify the installed version using 'python -c "import shiny; print(shiny.version)"' ensures version >= 1.6.4.
  3. Deploy WAF rules blocking HTTP GET parameters containing '_state_id=' with '..' or absolute paths.

References


Read the full report for CVE-2026-108258 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)