High severityNVD Advisory· Published Aug 1, 2022· Updated Apr 22, 2025
Improper Limitation of a Pathname to a Restricted Directory in sanic
CVE-2022-35920
Description
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using app.static if using encoded %2F URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sanicPyPI | >= 22.0.0, < 22.6.1 | 22.6.1 |
sanicPyPI | >= 21.0.0, < 21.12.2 | 21.12.2 |
sanicPyPI | < 20.12.7 | 20.12.7 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-8cw9-5hmv-77w6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-35920ghsaADVISORY
- github.com/sanic-org/sanic/issues/2478ghsax_refsource_MISCWEB
- github.com/sanic-org/sanic/pull/2495ghsax_refsource_MISCWEB
- github.com/sanic-org/sanic/security/advisories/GHSA-8cw9-5hmv-77w6ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.