CVE-2022-35920High· 8.3▾ Twilightsanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
0.9% → 1.1%
Access to lateral directories when using app.static if using encoded %2F URLs. Parent directory traversal is not impacted.
https://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495
If you have any questions or comments about this advisory:
sanic >= 22.0.0, < 22.6.1sanic >= 21.0.0, < 21.12.2sanic < 20.12.7Upgrade to a patched release:
sanic 22.6.1sanic 21.12.2sanic 20.12.7Connected by shared product, vendor, weakness, or advisory.