{"id":"CVE-2026-79318","title":"web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).","summary":"web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-22"],"published":"2026-09-21","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79318","references":[{"url":"https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79318.md","label":"cve@mitre.org"},{"url":"https://github.com/web2py/web2py","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00559,"epssPercentile":0.45408,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-22T14:52:01.088143Z"},"ingestedAt":"2026-09-21T20:52:58.286Z","slug":"CVE-2026-79318","body":"## Overview\n\nweb2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":209082,"id":"CVE-2026-79318","ts":1790089536260,"field":"cvss","old":null,"new":"6.5"},{"seq":209081,"id":"CVE-2026-79318","ts":1790089536260,"field":"severity","old":"none","new":"medium"}]}