VDB
Sign up
CRITICAL10.0

PYSEC-2026-512

Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component

Quick fix

PYSEC-2026-512 — radicale: upgrade to the fixed version with the command below.

pip install --upgrade 'radicale>=1.1'

Details

The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/radicale
Introduced in: 0Fixed in: 1.1
Fixpip install --upgrade 'radicale>=1.1'

References