Listen to this Post
A path traversal vulnerability exists within the bookmark-restore functionality of the Shiny for Python framework. When a client interacts with a Shiny web application, the application checks incoming HTTP request parameters for bookmark restoration triggers. Specifically, the framework processes the `_state_id_` parameter provided in the query string and directly concatenates its value into the local server-side directory path structure located at `
Because the input parameter fails to restrict path navigation sequences, an attacker can supply absolute path strings or relative parent directory sequences such as ... This allows the application process to navigate out of the intended `values.json.
In default configurations, this restore logic executes unconditionally whenever any query string parameter is present—even if the developer explicitly disabled session bookmarking via bookmark_store="disable". This enables unauthenticated attackers to perform server-side file existence and JSON structure probing across system paths. Furthermore, in applications configured with `bookmark_store=”server”` that implement ui.input_file(), the restore routine copies files out of the targeted directory, allowing complete unauthorized read access to file contents matching the expected filenames.
DailyCVE Form:
Platform: Shiny for Python
Version: 1.4.0 to 1.6.3
Vulnerability: Path Traversal
Severity: Medium (CVSS 6.9)
date: September 14 2026
Prediction: Already Patched (1.6.4)
What Undercode Say: Analytics
Bash Commands and Verification Code
1. Vulnerability Probe (Curl Command)
curl -i -s "http://target-shiny-app.local/?_state_id_=../../../../tmp/target_dir"
2. Reverse Proxy Mitigation (Nginx Configuration)
if ($args ~ "<em>state_id</em>=") {
return 403;
}
3. Standard Upgrade Command
pip install --upgrade shiny
How Exploit: (Educational Purposes!)
- Reconnaissance & Directory Selection: An attacker identifies a target host running Shiny for Python version 1.4.0 through 1.6.3. The attacker selects a target directory path where target standard JSON configuration or session files (e.g., `input.json` or
values.json) might reside. - Constructing Traversing Query Parameters: The attacker crafts an HTTP GET request appending the `_state_id_` parameter with relative path traversal sequences targeting the external directory:
`GET /?_state_id_=../../../../tmp/target_dir HTTP/1.1`
3. Server-Side Trigger & File Read:
Default Mode: The server attempts to open and parse `values.json, leaking file validity information via error/response behaviors.
Server Bookmark Mode: If the application uses `bookmark_store=”server”` alongside ui.input_file(), the restore sequence executes file copies out of the traversed path directly into the application context, exfiltrating file contents.
Protection:
Upgrade Software Package: Update the Python `shiny` package immediately to version `1.6.4` or higher via pip install --upgrade shiny. The patch enforces strict regex validation ([A-Za-z0-9_-]+) on bookmark IDs and gates restore routines based on the global `bookmark_store` setting.
Web Application Firewall / Proxy Rule: Filter or strip the `_state_id_` query parameter at the load balancer or reverse proxy level (e.g., Nginx, HAProxy, AWS WAF) before requests reach the application backend.
Impact:
Information Disclosure: Unauthenticated attackers can probe the underlying filesystem for directory existence and JSON schema validity.
Arbitrary File Read: On systems configured with server-side bookmark storage and file input components, attackers can read sensitive file data from targeted server directories.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

