Executive brief
Shamefile is a tool used to track and manage undocumented linter warnings in software projects. A security flaw in the 'shame next' command allows a specially crafted configuration file to trick the tool into reading sensitive files from the user's computer. If a developer runs this command on a malicious project, private data from outside the project folder could be exposed in their terminal.
Technical details
A path traversal vulnerability (CWE-22) exists in the `shame next` command of the Shamefile linter. The root cause was the snippet renderer opening and reading files directly from disk based on the `location` field in `shamefile.yaml` without proper validation. An attacker can provide a crafted YAML file containing absolute paths or parent directory references (..), allowing them to disclose one line of any file readable by the current user when the command is executed. The vulnerability is fixed in version 0.1.7 by refactoring the renderer to use cached content from the registry instead of reading directly from the file system.
Affected products
- BKDDFS shamefile < 0.1.7
Timeline
- 2026-05-17: patched: Fix committed and version 0.1.7 released.
- 2026-07-20: disclosed: CVE-2026-47144 published.
References
- https://github.com/BKDDFS/shamefile/commit/77b0aeea318503582818c708518c601fedc43557
- https://github.com/BKDDFS/shamefile/pull/80
- https://github.com/BKDDFS/shamefile/releases/tag/v0.1.7
- https://github.com/BKDDFS/shamefile/security/advisories/GHSA-x6p3-76f2-xxvh
- https://github.com/pypa/advisory-database/tree/main/vulns/shamefile/PYSEC-2026-3065.yaml