---
id: CVE-2025-55149
aliases:
  - GHSA-rrgf-hcr9-jq6h
  - PYSEC-2026-1967
title: TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
summary: TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
severity: medium
vendor: tiny-scientist
product: tiny-scientist
ecosystem: pip
affected:
  - tiny-scientist <= 1.1.0
published: '2025-08-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:27.514533341Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-rrgf-hcr9-jq6h'
references:
  - url: >-
      https://github.com/ulab-uiuc/tiny-scientist/security/advisories/GHSA-rrgf-hcr9-jq6h
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55149'
  - url: >-
      https://github.com/ulab-uiuc/tiny-scientist/commit/7fd42873603012acb8c55a4fc3eaac9ab18e6559
  - url: 'https://github.com/ulab-uiuc/tiny-scientist'
tags:
  - osv
  - pip
epss: 0.00645
epssPercentile: 0.49507
ingestedAt: '2026-07-08T18:25:53.016Z'
---

## Overview

## Description
A critical path traversal vulnerability (CWE-22) has been identified in the `review_paper` function in `backend/app.py`. The vulnerability allows malicious users to access arbitrary PDF files on the server by providing crafted file paths that bypass the intended security restrictions.

## Impact
This vulnerability allows attackers to:
- Read any PDF file accessible to the server process
- Potentially access sensitive documents outside the intended directory
- Perform reconnaissance on the server's file system structure

## Vulnerable Code
The issue occurs in the `review_paper` function around line 744:

```python
if pdf_path.startswith("/api/files/"):
    # Safe path handling for API routes
    relative_path = pdf_path[len("/api/files/"):]
    generated_base = os.path.join(project_root, "generated")
    absolute_pdf_path = os.path.join(generated_base, relative_path)
else:
    absolute_pdf_path = pdf_path  # VULNERABLE: Direct use of user input
```

## Proof of Concept
```bash
curl -X POST http://localhost:5000/api/review \
  -H "Content-Type: application/json" \
  -d '{"pdf_path": "/etc/passwd"}'
```

## Credit
This vulnerability was discovered and reported by Ruizhe.

## Affected packages

- `tiny-scientist <= 1.1.0`

## Remediation

Refer to the advisory for the patched release.
