{"id":"CVE-2026-108258","title":"Shiny for Python is a framework for building interactive web applications in Python","summary":"Shiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shiny_bookmarks directory without validati…","severity":"medium","cwe":["CWE-22"],"vendor":"shiny","product":"shiny","affected":["shiny >= 1.4.0, <= 1.6.3"],"patched":["shiny 1.6.4"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T21:17:03.853","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108258","references":[{"url":"https://github.com/posit-dev/py-shiny/commit/1d8ecb46cbc9621b7dc8812111d26692e086b376","label":"security-advisories@github.com"},{"url":"https://github.com/posit-dev/py-shiny/releases/tag/v1.6.4","label":"security-advisories@github.com"},{"url":"https://github.com/posit-dev/py-shiny/security/advisories/GHSA-47c3-hpmg-7j6p","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-47c3-hpmg-7j6p"}],"tags":["nvd","ghsa","pip"],"aliases":["GHSA-47c3-hpmg-7j6p"],"ecosystem":"pip","ingestedAt":"2026-10-09T21:12:42.323Z","slug":"CVE-2026-108258","body":"## Overview\n\nShiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shiny_bookmarks directory without validating that it is a single safe path segment. An unauthenticated request can use parent-directory segments or an absolute path to make the server open input.json and values.json outside the bookmark store, even when bookmark_store is set to disable. In applications configured with bookmark_store set to server and using ui.input_file(), the restore handler can additionally copy and expose an attacker-selected file from an attacker-selected directory. This issue is fixed in version 1.6.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-108258)\n\nAffected packages:\n\n- `shiny >= 1.4.0, <= 1.6.3`\n\nPatched in:\n\n- `shiny 1.6.4`\n\nSource: https://github.com/advisories/GHSA-47c3-hpmg-7j6p","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}