HIGH7.5
PYSEC-2026-1287
Dagster vulnerable to Path Traversal attack through its /logs endpoint
Quick fix
PYSEC-2026-1287 — dagster: upgrade to the fixed version with the command below.
pip install --upgrade 'dagster>=1.5.11'Details
Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-51232[ADVISORY]
- https://github.com/dagster-io/dagster/pull/18462[WEB]
- https://github.com/dagster-io/dagster/commit/dbb064c2ddda74265b8174edd9775e1302ca6ba0[WEB]
- https://github.com/dagster-io/dagster[PACKAGE]
- https://pypi.org/project/dagster[PACKAGE]
- https://github.com/advisories/GHSA-q93c-p2mw-p23f[ADVISORY]