Skip to content
DagsterGHSA-h7x8-jv97-fvvm

Dagster Local File Inclusion vulnerability

Medium6.6CVE-2025-51481 · Published Jul 22, 2025 · updated Jul 7, 2026

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

GitHub advisory

Affected versions

PackageAffectedFixed in
dagster
PyPI
< 1.10.161.10.16
Details and references

More Dagster advisories

All Dagster

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.