Executive brief
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
Affected products
- PyPI sanic
Junglewise Threat Intelligence
CVE-2022-35920 · Severity: low · CVSS 3.1 · Published 2026-07-06
Technologies: sanic (PyPI). Vendors: PyPI.
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs