CVE-2021-43494
Description
OpenCV-REST-API master branch as of commit 69be158c05d4dd5a4aff38fdc680a162dd6b9e49 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in OpenCV-REST-API master branch (commit 69be158c04d4dd5a4aff38fdc680a162dd6b9e49) allows disclosure of arbitrary system files via a crafted URI.
Vulnerability
A directory traversal vulnerability exists in the static_outputs_view route of OpenCV-REST-API master branch as of commit 69be158c05d4dd5a4aff38fdc680a162dd6b9e49 [1]. The route uses send_from_directory() with attacker-controlled path and filename parameters derived from the user-supplied <path:path> variable. The code does not sanitise or validate the path for directory traversal sequences, enabling an attacker to access arbitrary files outside the intended directory.
Exploitation
An attacker can exploit this by sending a crafted HTTP request to the /static/outputs/ endpoint with path traversal sequences (e.g., ../) in the URI. For example, requesting /static/outputs/../../../../etc/passwd will return the contents of the /etc/passwd file [1]. No authentication is required, and the attacker only needs network access to the server.
Impact
Successful exploitation leads to disclosure of critical secrets stored anywhere on the filesystem, including application source code, configuration files, and system files. This can significantly aid further attacks, potentially leading to remote code execution [1]. The disclosure is limited by system access controls, such as locked files on Windows.
Mitigation
As of the available references, no official fix has been released for this vulnerability [1]. The issue was reported and acknowledged in the project's issue tracker. Users should apply input validation and sanitisation to the path parameter, or avoid using send_from_directory with user-controlled input until a patched version is available.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- OpenCV-REST-API/OpenCV-REST-APIdescription
- Range: = master branch at commit 69be158c05d4dd5a4aff38fdc680a162dd6b9e49
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/codingforentrepreneurs/OpenCV-REST-API/issues/2mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.