{"id":"CVE-2024-56142","aliases":["GHSA-m9hc-vxjj-4x6q","PYSEC-2026-1778"],"title":"PGHoard Path Traversal vulnerability","summary":"PGHoard Path Traversal vulnerability","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","vendor":"pghoard","product":"pghoard","ecosystem":"pip","affected":["pghoard < 2.6.1-rc"],"patched":["pghoard 2.6.1-rc"],"published":"2024-12-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-m9hc-vxjj-4x6q","references":[{"url":"https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-m9hc-vxjj-4x6q"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56142"},{"url":"https://github.com/Aiven-Open/pghoard/commit/fe9947642cc73bcacf6d19b93eb98f442223fb47"},{"url":"https://github.com/Aiven-Open/pghoard"}],"tags":["osv","pip"],"epss":0.00414,"epssPercentile":0.35298,"ingestedAt":"2026-07-08T18:25:51.196Z","slug":"CVE-2024-56142","body":"## Overview\n\nA vulnerability has been discovered that could allow an attacker to acquire disk access with privileges equivalent to those of pghoard, allowing for unintended path traversal.  Depending on the permissions/privileges assigned to pghoard, this could allow disclosure of sensitive information.\n\n## Affected packages\n\n- `pghoard < 2.6.1-rc`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pghoard 2.6.1-rc`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}