VDB
Sign up
CRITICAL9.3

PYSEC-2026-541

Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafely

Details

The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/shiva
Introduced in: 0

No fixed version published yet for shiva (pip). Pin to a known-safe version or switch to an alternative.

References