CRITICAL9.3
PYSEC-2026-541
Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafely
Details
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/shiva
Introduced in:
0No fixed version published yet for shiva (pip). Pin to a known-safe version or switch to an alternative.