PT-2026-35587 · Pypi · Engineer-Your-Data

Smallw

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7214

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eghuzefa engineer-your-data versions prior to 0.1.4
Description A path traversal issue exists in the src/server.py file. The manipulation of the WORKSPACE PATH argument within the read file(), write file(), list files(), and file inf() functions allows a remote attacker to access or modify files outside the intended directory. Path traversal is a technique that allows an attacker to read or write files on the server by manipulating file paths using special sequences like dot-dot-slash (../).
Recommendations As a temporary workaround, restrict access to the read file(), write file(), list files(), and file inf() functions or avoid using the WORKSPACE PATH argument until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7214

Affected Products

Engineer-Your-Data