Junglewise Threat Intelligence

CVE-2024-30265: PYSEC-2026-2027 - Voilà Local file inclusion

CVE-2024-30265 · Severity: low · CVSS 3.1 · Published 2026-07-07

Vendors: PyPI.

Executive brief

Voilà is a framework for turning Jupyter notebooks into interactive web applications. A local file inclusion vulnerability allows anyone with network access to the server to download arbitrary files readable by the Voilà process user, such as configuration files, source code, or system files. Authentication requirements vary depending on deployment configuration.

Technical details

The vulnerability exists in the "/static" route handler where the root path is incorrectly hardcoded to "/" instead of the intended static directory. When tornado.web.StaticFileHandler processes requests with user-supplied paths, it combines this root with the requested path, allowing traversal outside the static directory via relative paths. An unauthenticated attacker on the network can craft requests like `GET /static/etc/passwd` to retrieve arbitrary files accessible to the Voilà server process. The bug stems from line 664 of voila/app.py, present since September 2018. Patches are available in versions 0.2.17+, 0.3.8+, 0.4.4+, and 0.5.6+.

Affected products

  • Voilà Voilà 0.0.2 to 0.2.16, 0.3.0a0 to 0.3.7, 0.4.0a0 to 0.4.3, 0.5.0a0 to 0.5.5

Timeline

  • 2024-04-03: disclosed
  • 2024-04-03: patched: Fixed in versions 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+

References