MEDIUM6.6
PYSEC-2026-1286
Dagster Local File Inclusion vulnerability
Quick fix
PYSEC-2026-1286 — dagster: upgrade to the fixed version with the command below.
pip install --upgrade 'dagster>=1.10.16'Details
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-51481[ADVISORY]
- https://github.com/dagster-io/dagster/pull/30002[WEB]
- https://github.com/dagster-io/dagster/commit/3a3cec2b51577c4970e6fc4c199cda6418c09a9d[WEB]
- https://github.com/dagster-io/dagster[PACKAGE]
- https://github.com/pypa/advisory-database/tree/main/vulns/dagster-ge/PYSEC-2025-102.yaml[WEB]
- https://www.gecko.security/blog/cve-2025-51481[WEB]
- https://pypi.org/project/dagster[PACKAGE]
- https://github.com/advisories/GHSA-h7x8-jv97-fvvm[ADVISORY]