High severity7.5NVD Advisory· Published Jun 1, 2023· Updated Jun 17, 2026
CVE-2023-29159
CVE-2023-29159
Description
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
starlettePyPI | >= 0.13.5, < 0.27.0 | 0.27.0 |
Affected products
2Patches
Vulnerability mechanics
References
9- github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84pxnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-v5gw-mw7f-84pxghsaADVISORY
- jvn.jp/en/jp/JVN95981715/nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2023-29159ghsaADVISORY
- github.com/encode/starlette/blob/4bab981d9e870f6cee1bd4cd59b87ddaf355b2dc/starlette/staticfiles.pyghsaWEB
- github.com/encode/starlette/commit/1797de464124b090f10cf570441e8292936d63e3ghsaWEB
- github.com/encode/starlette/releases/tag/0.27.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2023-83.yamlghsaWEB
- jvn.jp/en/jp/JVN95981715ghsaWEB
News mentions
0No linked articles in our index yet.