Advisories for Pypi/Shiny package

2026

Shiny for Python has path traversal in bookmark restore

Shiny for Python's bookmark-restore path accepted a client-supplied state_id query-string value and joined it into the server-side bookmark directory (<cwd>/shiny_bookmarks/<id>) without validating it. A value containing .. path segments, or an absolute path, could therefore cause the server to open and parse input.json and values.json from a directory outside the bookmark store. On a default application the restore was attempted whenever the client supplied a URL query string — including …