PT-2026-2107 · Werkzeug · Werkzeug

Yueyuel

·

Published

2026-01-08

·

Updated

2026-05-20

·

CVE-2026-21860

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Werkzeug versions prior to 3.1.5
Description Werkzeug’s safe join function improperly handles path segments containing Windows device names with file extensions or trailing spaces. Windows device names, such as CON and AUX, are implicitly present and readable in every directory and are accepted with file extensions (e.g., CON.txt) or trailing spaces (e.g., CON ). This can lead to unauthorized access or manipulation of system resources.
Recommendations Update Werkzeug to version 3.1.5 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-21860
GHSA-87HC-H4R5-73F7

Affected Products

Werkzeug