{"id":"CVE-2022-1554","aliases":["GHSA-694v-63fq-fmr4","PYSEC-2026-749"],"title":"Path Traversal in scout-browser","summary":"Path Traversal in scout-browser","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L","vendor":"scout-browser","product":"scout-browser","ecosystem":"pip","affected":["scout-browser < 4.52"],"patched":["scout-browser 4.52"],"published":"2022-05-04","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-694v-63fq-fmr4","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1554"},{"url":"https://github.com/Clinical-Genomics/scout/issues/3128"},{"url":"https://github.com/Clinical-Genomics/scout/issues/3302"},{"url":"https://github.com/Clinical-Genomics/scout/pull/3303"},{"url":"https://github.com/clinical-genomics/scout/commit/952a2e2319af2d95d22b017a561730feac086ff1"},{"url":"https://github.com/clinical-genomics/scout"},{"url":"https://huntr.dev/bounties/7acac778-5ba4-4f02-99e2-e4e17a81e600"}],"tags":["osv","pip"],"epss":0.01345,"epssPercentile":0.69731,"ingestedAt":"2026-07-08T18:25:46.318Z","slug":"CVE-2022-1554","body":"## Overview\n\nScout is a Variant Call Format (VCF) visualization interface. The Pypi package `scout-browser` is vulnerable to path traversal due to `send_file` call in versions prior to 4.52.\n\n## Affected packages\n\n- `scout-browser < 4.52`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `scout-browser 4.52`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}