Executive brief
Emmett is a Python web framework used to build and serve web applications. A security flaw in how the framework handles internal files allows unauthorized users to access sensitive files on the server, such as application source code or configuration files. This could lead to the exposure of private data or help an attacker gain further control over the system.
Technical details
A path traversal vulnerability exists in the RSGI static handler of the Emmett framework. The vulnerability is located in the handling of internal asset paths starting with /__emmett__. By sending specially crafted HTTP requests containing dot-dot-slash (../) sequences, a remote, unauthenticated attacker can bypass directory restrictions. This allows for the retrieval of arbitrary files from the underlying server's filesystem that the web server process has permission to read. The issue is present in versions 2.5.0 through 2.8.0 and is resolved in version 2.8.1.
Affected products
- emmett-framework Emmett >= 2.5.0, < 2.8.1
Timeline
- 2026-04-07: disclosed
- 2026-04-07: advisory
- 2026-04-07: patched: Fixed in version 2.8.1