CVE-2022-1554Medium· 6.8▾ SunlitPath Traversal in scout-browser
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.3%
1.3% → 1.3%
Scout is a Variant Call Format (VCF) visualization interface. The Pypi package scout-browser is vulnerable to path traversal due to send_file call in versions prior to 4.52.
scout-browser < 4.52Upgrade to a patched release:
scout-browser 4.52Connected by shared product, vendor, weakness, or advisory.