VDB
Sign up
—

PYSEC-2026-2045

Werkzeug safe_join not safe on Windows

Quick fix

PYSEC-2026-2045 — werkzeug: upgrade to the fixed version with the command below.

pip install --upgrade 'werkzeug>=3.0.6'

Details

On Python < 3.11 on Windows, `os.path.isabs()` does not catch UNC paths like `//server/share`. Werkzeug's `safe_join()` relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/werkzeug
Introduced in: 0Fixed in: 3.0.6
Fixpip install --upgrade 'werkzeug>=3.0.6'

References