HIGH7.5
PYSEC-2026-1387
Path traversal in flaskcode
Details
An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/flaskcode
Introduced in:
0No fixed version published yet for flaskcode (pip). Pin to a known-safe version or switch to an alternative.