---
id: CVE-2024-56142
aliases:
  - GHSA-m9hc-vxjj-4x6q
  - PYSEC-2026-1778
title: PGHoard Path Traversal vulnerability
summary: PGHoard Path Traversal vulnerability
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: pghoard
product: pghoard
ecosystem: pip
affected:
  - pghoard < 2.6.1-rc
patched:
  - pghoard 2.6.1-rc
published: '2024-12-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-m9hc-vxjj-4x6q'
references:
  - url: >-
      https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-m9hc-vxjj-4x6q
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-56142'
  - url: >-
      https://github.com/Aiven-Open/pghoard/commit/fe9947642cc73bcacf6d19b93eb98f442223fb47
  - url: 'https://github.com/Aiven-Open/pghoard'
tags:
  - osv
  - pip
epss: 0.00412
epssPercentile: 0.32789
ingestedAt: '2026-07-08T18:25:51.196Z'
---

## Overview

A vulnerability has been discovered that could allow an attacker to acquire disk access with privileges equivalent to those of pghoard, allowing for unintended path traversal.  Depending on the permissions/privileges assigned to pghoard, this could allow disclosure of sensitive information.

## Affected packages

- `pghoard < 2.6.1-rc`

## Remediation

Upgrade to a patched release:

- `pghoard 2.6.1-rc`
