DagsterGHSA-h7x8-jv97-fvvm
Dagster Local File Inclusion vulnerability
Medium6.6CVE-2025-51481 · Published Jul 22, 2025 · updated Jul 7, 2026
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dagster PyPI | < 1.10.16 | 1.10.16 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2025-51481, PYSEC-2025-102, PYSEC-2026-1286
- nvd.nist.gov/vuln/detail/CVE-2025-51481
- github.com/dagster-io/dagster/pull/30002
- github.com/dagster-io/dagster/commit/3a3cec2b51577c4970e6fc4c199cda6418c09a9d
- github.com/dagster-io/dagster
- github.com/pypa/advisory-database/tree/main/vulns/dagster-ge/PYSEC-2025-102.yaml
- www.gecko.security/blog/cve-2025-51481
More Dagster advisories
All Dagster| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 18 | Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations | High8.3 | 1.13.1 |
| Jul 72025 | Dagster vulnerable to Path Traversal attack through its /logs endpoint | Medium7.5 | 1.5.11 |