Safety vulnerability ID: 54697
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Mkdocs 1.2.3 includes a fix for CVE-2021-40978: Built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain sensitive information.
NOTE: the vendor doesn't agree this is a security flaw. "It should be mentioned the dev server is known to not be secure and should not be used in a sensitive environment. The security flaw is using the dev-server in an unsafe way, e.g., as a public server and not just as a development server."
Latest version: 1.6.1
Project documentation with Markdown.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application