CVE Feed

    Dashboard / CVE / CVE-2024-39903

    CVE-2024-39903

    Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.

    Published:Jul 12, 2024
    Last Modified:Apr 10, 2025
    EPS:Jul 12, 2024
    EPSS Score:0.39222
    CVSS Score:8.6

    Affected Products

    Vendor
    Widgetti
    Product
    Solara

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High