{"id":"CVE-2026-38360","aliases":["GHSA-3rf6-x59v-5jfv","PYSEC-2026-320"],"title":"dash-uploader has a directory traversal vulnerability","summary":"dash-uploader has a directory traversal vulnerability","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"dash-uploader","product":"dash-uploader","ecosystem":"pip","affected":["dash-uploader >= 0.1.0, <= 0.7.0a2"],"published":"2026-05-08","updated":"2026-08-31","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3rf6-x59v-5jfv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-38360"},{"url":"https://github.com/fohrloop/dash-uploader/issues/153"},{"url":"https://github.com/github/advisory-database/pull/7635"},{"url":"https://github.com/a1ohadance/CVE-2026-38360"},{"url":"https://github.com/fohrloop/dash-uploader"},{"url":"https://github.com/fohrloop/dash-uploader/blob/dev/dash_uploader/httprequesthandler.py"},{"url":"https://github.com/fohrloop/dash-uploader/blob/stable/dash_uploader/httprequesthandler.py"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/dash-uploader/PYSEC-2026-320.yaml"}],"tags":["osv","pip","exploit-available"],"epss":0.05982,"epssPercentile":0.93042,"ingestedAt":"2026-09-02T19:31:22.601Z","exploits":{"github":1,"githubRepos":["https://github.com/a1ohadance/CVE-2026-38360"],"nuclei":["CVE-2026-38360"],"checkedAt":"2026-09-21T15:28:48.166Z"},"exploitAvailable":true,"slug":"CVE-2026-38360","body":"## Overview\n\n### Impact\n\nAn unauthenticated path traversal vulnerability exists in [dash-uploader](https://pypi.org/project/dash-uploader/) versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at `dash_uploader/httprequesthandler.py` reads three form parameters (`upload_id`, `resumableFilename`, `resumableIdentifier`) from `request.form.get()` and passes them directly to `os.path.join()` and `os.makedirs()` without any sanitization.\n\nA single unauthenticated `POST /API/dash-uploader` request with `upload_id` set to a relative path (e.g. `../../etc/cron.d` or `../venv/lib/python3.13/site-packages`) escapes the application's `uploads/` directory and writes the supplied file content to the chosen target path under the privilege of the gunicorn / WSGI process.\n\nWhen the chosen target is a Python `site-packages` directory and the dropped file is a `.pth` file containing an `import`-prefixed line, Python's `site` module executes that line on the next interpreter startup, yielding remote code execution. Other escalation paths reachable from the same primitive include overwriting the running WSGI module, dropping `~/.ssh/authorized_keys`, or writing JavaScript into a Dash-served `assets/` directory for stored XSS.\n\n### Affected versions\n\nAll 16 published PyPI releases (`0.1.0` through `0.7.0a2`) are affected. The package repository was archived on 2025-07-19; **no patched version exists**.\n\n### Mitigation\n\nReplace `dash-uploader` with an alternative file-upload component (for example, `dash-resumable-upload`, server-rendered `<input type=\\\"file\\\">` plus a hardened Flask endpoint, or a maintained Dash community alternative). There is no upstream fix path.\n\nWhile a replacement is being deployed, mitigations include:\n\n* Block `POST /API/dash-uploader` at an upstream proxy, OR\n* Run the application as an unprivileged user with no write access to its own `site-packages`, OR\n* Use a read-only filesystem for the application's code directories.\n\n## Affected packages\n\n- `dash-uploader >= 0.1.0, <= 0.7.0a2`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":53.9,"likelihood":1.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5140,"id":"CVE-2026-38360","ts":1788887250751,"field":"exploit_available","old":"false","new":"true"},{"seq":4023,"id":"CVE-2026-38360","ts":1788886366631,"field":"exploit_available","old":"true","new":"false"},{"seq":2834,"id":"CVE-2026-38360","ts":1788883033354,"field":"exploit_available","old":"false","new":"true"},{"seq":1863,"id":"CVE-2026-38360","ts":1788882436192,"field":"exploit_available","old":"true","new":"false"},{"seq":961,"id":"CVE-2026-38360","ts":1788881870159,"field":"exploit_available","old":"false","new":"true"}]}