Skip to content
StreamlitGHSA-8qw9-gf7w-42x5

Minor fix to previous patch for CVE-2022-35918

Medium5.3Published Jan 12, 2024 · updated Jun 30, 2026

### Impact The initial vulnerability identified in Streamlit apps using custom components, allowing for directory traversal attacks, was addressed in version 1.11.1. However, a minor issue persisted, which could still potentially expose certain files on the server file-system under specific conditions. ### Patches We released an update in version 1.30.0 to further tighten security measures. Users are strongly advised to update to version 1.30.0 immediately for optimal security. ### Workarounds No additional workarounds are necessary once the update to version 1.30.0 is applied. ### For more information If you have any questions or comments about this advisory: * Email us at [security@streamlit.io](mailto:security@streamlit.io)

GitHub advisory

Affected versions

PackageAffectedFixed in
streamlit
PyPI
>= 0.63.0, < 1.30.01.30.0
Details and references

More Streamlit advisories

All Streamlit

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.