MEDIUM6.5
PYSEC-2026-637
Path traversal in FreeTAKServer-UI
Details
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/freetakserver-ui
Introduced in:
0No fixed version published yet for freetakserver-ui (pip). Pin to a known-safe version or switch to an alternative.