Vulnerability DatabaseCVE-2026-108258

CVE-2026-108258: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-108258 is a path traversal vulnerability (CWE-22) in Shiny for Python's bookmark-restore functionality that allows unauthenticated remote attackers to read files outside the intended bookmark directory. It affects shiny (pip) versions 1.4.0 through 1.6.3; versions prior to 1.4.0 are not affected as bookmarking was introduced in that release. The vulnerability was reported by @0xRenSec, published to the GitHub Advisory Database on September 3, 2026, and patched in version 1.6.4 released on October 9, 2026. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, py-shiny Release).

Technical details

The root cause (CWE-22) is that the bookmark-restore handler accepted the client-supplied _state_id_ query-string parameter and joined it directly into the server-side /shiny_bookmarks/ directory path without any validation. An attacker could supply .. path segments or an absolute path as the _state_id_ value, causing the server to open and parse input.json and values.json from arbitrary directories outside the bookmark store. Critically, the restore logic executed even when bookmark_store was set to "disable", meaning no application opt-in was required. For applications using bookmark_store="server" with ui.input_file(), the file-input restore handler used shutil.copy2() (which follows symlinks) to copy files out of the restore directory, enabling an attacker to read the full contents of any attacker-selected file accessible to the web server process (GitHub Advisory, Fix Commit).

Impact

The primary impact is unauthorized file disclosure. In the baseline case (any application running an affected version), an unauthenticated attacker can probe for the existence and JSON-validity of arbitrary files named input.json or values.json anywhere on the server filesystem accessible to the web process. In the more severe case — applications configured with bookmark_store="server" and ui.input_file() — an attacker can read the complete contents of any file accessible to the web server process by directing the restore handler to copy it, potentially exposing credentials, configuration files, or sensitive application data. There is no integrity or availability impact reported (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable Shiny application. The EPSS score is reported as 0.0, reflecting the current absence of observed exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Shiny for Python applications running versions 1.4.0–1.6.3 (e.g., via Shodan, Censys, or by inspecting HTTP response headers/page content for Shiny framework indicators).
  2. Craft malicious _state_id_ parameter: Construct a URL query string with a traversal payload in the _state_id_ parameter, such as ?_state_id_=../../etc or ?_state_id_=/etc, targeting a directory known to contain input.json or values.json, or probing for their existence.
  3. Send HTTP request: Issue an unauthenticated HTTP GET request to the application root (e.g., GET /?_state_id_=../../target_dir HTTP/1.1). The server will attempt to open and parse input.json and values.json from the traversed path.
  4. Probe for file existence/validity: Observe application behavior or error responses to infer whether the targeted path exists and contains valid JSON — this constitutes a server-side oracle for file existence.
  5. Escalate on bookmark_store="server" + ui.input_file() apps: If the target application uses server-side bookmarking with file inputs, craft a _state_id_ pointing to a directory containing a sensitive file (e.g., ../../app_config), causing the restore handler to copy and expose the file's contents to the application session (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Unusual HTTP GET requests to the application root containing _state_id_ query parameters with .., /, or absolute path patterns (e.g., ?_state_id_=../../etc, ?_state_id_=/etc/passwd).
  • Logs: Web server or application access logs showing repeated requests with malformed or path-traversal-style _state_id_ values; server-side shiny.bookmark._restore_state logger warnings such as "Could not restore bookmarked state" triggered by invalid bookmark IDs.
  • File System: Unexpected file copy operations or access to files outside the shiny_bookmarks/ directory by the web server process; access timestamps updated on sensitive files (e.g., configuration files, credential stores) not normally accessed by the Shiny process.
  • Process: File open/read system calls by the Shiny Python process targeting paths outside the application's working directory or shiny_bookmarks/ folder, observable via auditd or similar host-based monitoring (GitHub Advisory, Fix Commit).

Mitigation and workarounds

The primary remediation is to upgrade Shiny for Python to version 1.6.4 or later using pip install --upgrade shiny. The fix validates bookmark IDs against the allowlist regex [A-Za-z0-9_-]+ (a single safe path segment), gates restore logic on the application's bookmark_store setting, and prevents symlink-following in file-input restore. For deployments that cannot upgrade immediately, the only effective workaround is to strip the _state_id_ query parameter from all incoming requests at a reverse proxy or load balancer — no application-level configuration (including setting bookmark_store="disable") mitigates the issue on affected versions. Disabling bookmarking functionality entirely at the proxy level is recommended as a temporary measure (GitHub Advisory, py-shiny Release).

Community reactions

The vulnerability was reported by security researcher @0xRenSec and disclosed via the GitHub Security Advisory program. The advisory was published by Shiny maintainer @schloerke on September 3, 2026, and made public on October 9, 2026. No significant broader media coverage or notable community commentary beyond the standard advisory channels has been identified (GitHub Advisory, py-shiny Release).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-108258MEDIUM6.9
  • Python logoPython
  • shiny
NoYesOct 09, 2026
CVE-2026-48484MEDIUM6.5
  • Python logoPython
  • pyload-ng
NoYesOct 09, 2026
GHSA-p3pr-8f3m-4qp8MEDIUM6.4
  • Python logoPython
  • pyload-ng
NoNoOct 09, 2026
CVE-2026-107841MEDIUM5.7
  • Python logoPython
  • pacioli-guard
NoYesOct 09, 2026
CVE-2026-75597MEDIUM5.3
  • Python logoPython
  • pyload-ng
NoYesOct 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management