{"id":"CVE-2023-52288","aliases":["GHSA-6h4q-63c5-qfqf","PYSEC-2026-1386"],"title":"Path traversal in flaskcode","summary":"Path traversal in flaskcode","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"flaskcode","product":"flaskcode","ecosystem":"pip","affected":["flaskcode <= 0.0.8"],"published":"2024-01-13","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-6h4q-63c5-qfqf","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-52288"},{"url":"https://gitlab.com/daniele_m/cve-list/-/blob/main/README.md"}],"tags":["osv","pip"],"epss":0.008,"epssPercentile":0.54609,"ingestedAt":"2026-07-08T18:25:46.473Z","slug":"CVE-2023-52288","body":"## Overview\n\nAn issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files.\n\n## Affected packages\n\n- `flaskcode <= 0.0.8`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}