---
id: CVE-2026-79318
title: >-
  web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is
  vulnerable to Directory Traversal in read_file()/write_file()
  (applications/admin/controllers/webservices.py).
summary: >-
  web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is
  vulnerable to Directory Traversal in read_file()/write_file()
  (applications/admin/controllers/webservices.py).
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-22
published: '2026-09-21'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79318'
references:
  - url: 'https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79318.md'
    label: cve@mitre.org
  - url: 'https://github.com/web2py/web2py'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00861
epssPercentile: 0.56793
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T14:52:01.088143Z'
ingestedAt: '2026-09-21T20:52:58.286Z'
---

## Overview

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
