DagsterGHSA-q93c-p2mw-p23f
Dagster vulnerable to Path Traversal attack through its /logs endpoint
Medium7.5CVE-2023-51232 · Published Jul 7, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dagster PyPI | < 1.5.11 | 1.5.11 |
Details and references
Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2023-51232, PYSEC-2026-1287
More Dagster advisories
All Dagster| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 222025 | Dagster Local File Inclusion vulnerability CVE-2025-51481Medium6.6fixed in 1.10.16 | Medium6.6 | 1.10.16 |
| Apr 18 | Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations CVE-2026-41490High8.3fixed in 1.13.1 | High8.3 | 1.13.1 |