Safety vulnerability ID: 50070
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Shiva throughout 0.10.0 allows absolute path traversal because the Flask send_file function is used unsafely. See CVE-2022-31558.
Latest version: 0.10.0
A RESTful API to your music collection
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. See CVE-2022-31558.
MISC:https://github.com/github/securitylab/issues/669#issuecomment-1117265726: https://github.com/github/securitylab/issues/669#issuecomment-1117265726
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application