Junglewise Threat Intelligence

CVE-2026-48544: Avaiga Taipy path traversal in ElementLibrary.get_resource

CVE-2026-48544 · Severity: high · CVSS 7.5 · Published 2026-05-27

Vendors: PyPI.

Executive brief

Taipy is a Python library used for building data-driven web applications. A security flaw in how the software handles file requests allows an unauthenticated attacker to access sensitive files on the server that should be restricted. This could lead to the exposure of private data or configuration files, potentially compromising the entire application environment.

Technical details

A path traversal vulnerability exists in the ElementLibrary.get_resource() method within taipy/gui/extension/library.py. The vulnerability stems from an incomplete path containment check that uses str.startswith() without ensuring a trailing path separator is present. An unauthenticated attacker can exploit this by sending crafted GET requests with path traversal segments (e.g., ../) targeting sibling directories that share a name prefix with the intended directory. Because Flask and Werkzeug preserve these segments during certain processing phases, the flawed check is bypassed, allowing unauthorized read access to files on the host system. The issue is addressed in commit 129fd40 by replacing the prefix check with a proper path relativity check.

Affected products

  • Avaiga Taipy <= 4.1.1

Timeline

  • 2026-04-29: disclosed: Issue reported on GitHub
  • 2026-04-30: patched: Fix merged into develop branch via commit 129fd40
  • 2026-05-27: advisory: GitHub Advisory and CVE published

References

Related threats