AVID-2026-R1058
Description
Streamlit directory traversal vulnerability (CVE-2022-35918)
Details
Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files, and potentially other sensitive information. An attacker can craft a malicious URL with file paths and the streamlit server would process that URL and return the contents of that file. This issue has been resolved in version 1.11.1. Users are advised to upgrade. There are no known workarounds for this issue.
Reason for inclusion in AVID: The CVE describes a directory traversal vulnerability in Streamlit, a popular framework used in ML/AI dashboards and pipelines. This directly impacts software commonly used to build, deploy, or serve AI applications, i.e., the AI software supply chain. It is a security vulnerability with potential data leakage, and the report provides explicit evidence (CVEID, description, remediation).
References
- NVD entry
- https://github.com/streamlit/streamlit/security/advisories/GHSA-v4hr-4jpx-56gc
- https://github.com/streamlit/streamlit/commit/80d9979d5f4a00217743d607078a1d867fad8acf
Affected or Relevant Artifacts
- Developer: streamlit
- Deployer: streamlit
- Artifact Details:
| Type | Name |
|---|---|
| System | streamlit |
Impact
AVID Taxonomy Categorization
- Risk domains: Security
- SEP subcategories: S0100: Software Vulnerability
- Lifecycle stages: L06: Deployment
CVSS
| Version | 3.1 |
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| Base Score | 6.5 |
| Base Severity | 🟠 Medium |
| Attack Vector | NETWORK |
| Attack Complexity | 🟢 Low |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | 🔴 High |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CWE
| ID | Description |
|---|---|
| CWE-22 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |
Other information
- Report Type: Advisory
- Credits:
- Date Reported: 2022-08-01
- Version: 0.3.3
- AVID Entry