---
id: CVE-2007-0902
aliases:
  - GHSA-mxh8-xgq9-w782
  - PYSEC-2026-679
title: MoinMoin Insertion of Sensitive Information into Log File
summary: MoinMoin Insertion of Sensitive Information into Log File
severity: medium
vendor: moin
product: moin
ecosystem: pip
affected:
  - 'moin >= 1.5.7, < 1.5.8'
patched:
  - moin 1.5.8
published: '2022-05-01'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-mxh8-xgq9-w782'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2007-0902'
  - url: 'https://moinmo.in/MoinMoinRelease1.5/CHANGES'
  - url: 'http://osvdb.org/33173'
  - url: 'http://secunia.com/advisories/24138'
  - url: 'http://secunia.com/advisories/24244'
  - url: 'http://www.securityfocus.com/bid/22515'
  - url: 'http://www.ubuntu.com/usn/usn-423-1'
tags:
  - osv
  - pip
epss: 0.01361
epssPercentile: 0.70098
ingestedAt: '2026-07-08T18:25:51.471Z'
---

## Overview

An information leak was discovered in MoinMoin's debug reporting version 1.5.7, which could expose information about the versions of software running on the host system.  MoinMoin administrators can add "show_traceback=0" to their site configurations to disable debug tracebacks.

## Affected packages

- `moin >= 1.5.7, < 1.5.8`

## Remediation

Upgrade to a patched release:

- `moin 1.5.8`
