CVE

CVE-2022-31502

CVE-2022-31502

The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Source: CVE-2022-31502

Exit mobile version