Skip to content
DagsterGHSA-q93c-p2mw-p23f

Dagster vulnerable to Path Traversal attack through its /logs endpoint

Medium7.5CVE-2023-51232 · Published Jul 7, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
dagster
PyPI
< 1.5.111.5.11
Details and references

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2023-51232, PYSEC-2026-1287

More Dagster advisories

All Dagster
DateAdvisory
Jul 222025Dagster Local File Inclusion vulnerability
CVE-2025-51481Medium6.6fixed in 1.10.16
Apr 18Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
CVE-2026-41490High8.3fixed in 1.13.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.