VDB
Sign up
CRITICAL9.8

PYSEC-2025-67

Quick fix

PYSEC-2025-67 — upsonic: upgrade to the fixed version with the command below.

pip install --upgrade 'upsonic>=0.56.0'

Details

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of the argument file.filename leads to path traversal. The exploit has been disclosed to the public and may be used.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/upsonic
Introduced in: 0Fixed in: 0.56.0
Fixpip install --upgrade 'upsonic>=0.56.0'

References