VDB
Sign up
CRITICAL9.3

PYSEC-2026-436

SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely

Details

The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. A patch is available on the `master` branch of the repository.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/opendiamond
Introduced in: 0

No fixed version published yet for opendiamond (pip). Pin to a known-safe version or switch to an alternative.

References