VDB
Sign up
HIGH7.5

PYSEC-2026-1287

Dagster vulnerable to Path Traversal attack through its /logs endpoint

Quick fix

PYSEC-2026-1287 — dagster: upgrade to the fixed version with the command below.

pip install --upgrade 'dagster>=1.5.11'

Details

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/dagster
Introduced in: 0Fixed in: 1.5.11
Fixpip install --upgrade 'dagster>=1.5.11'

References