VDB
Sign up
CRITICAL9.3

PYSEC-2026-309

ChainerRL Visualizer 0.1.1 vulnerable to Path Traversal via unsafe use of send_file function

Details

The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/chainerrl-visualizer
Introduced in: 0

No fixed version published yet for chainerrl-visualizer (pip). Pin to a known-safe version or switch to an alternative.

References