
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-108258 is a path traversal vulnerability (CWE-22) in Shiny for Python's bookmark-restore functionality that allows unauthenticated remote attackers to read files outside the intended bookmark directory. It affects shiny (pip) versions 1.4.0 through 1.6.3; versions prior to 1.4.0 are not affected as bookmarking was introduced in that release. The vulnerability was reported by @0xRenSec, published to the GitHub Advisory Database on September 3, 2026, and patched in version 1.6.4 released on October 9, 2026. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, py-shiny Release).
The root cause (CWE-22) is that the bookmark-restore handler accepted the client-supplied _state_id_ query-string parameter and joined it directly into the server-side /shiny_bookmarks/ directory path without any validation. An attacker could supply .. path segments or an absolute path as the _state_id_ value, causing the server to open and parse input.json and values.json from arbitrary directories outside the bookmark store. Critically, the restore logic executed even when bookmark_store was set to "disable", meaning no application opt-in was required. For applications using bookmark_store="server" with ui.input_file(), the file-input restore handler used shutil.copy2() (which follows symlinks) to copy files out of the restore directory, enabling an attacker to read the full contents of any attacker-selected file accessible to the web server process (GitHub Advisory, Fix Commit).
The primary impact is unauthorized file disclosure. In the baseline case (any application running an affected version), an unauthenticated attacker can probe for the existence and JSON-validity of arbitrary files named input.json or values.json anywhere on the server filesystem accessible to the web process. In the more severe case — applications configured with bookmark_store="server" and ui.input_file() — an attacker can read the complete contents of any file accessible to the web server process by directing the restore handler to copy it, potentially exposing credentials, configuration files, or sensitive application data. There is no integrity or availability impact reported (GitHub Advisory, Feedly).
No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable Shiny application. The EPSS score is reported as 0.0, reflecting the current absence of observed exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
_state_id_ parameter: Construct a URL query string with a traversal payload in the _state_id_ parameter, such as ?_state_id_=../../etc or ?_state_id_=/etc, targeting a directory known to contain input.json or values.json, or probing for their existence.GET /?_state_id_=../../target_dir HTTP/1.1). The server will attempt to open and parse input.json and values.json from the traversed path.bookmark_store="server" + ui.input_file() apps: If the target application uses server-side bookmarking with file inputs, craft a _state_id_ pointing to a directory containing a sensitive file (e.g., ../../app_config), causing the restore handler to copy and expose the file's contents to the application session (GitHub Advisory, Fix Commit)._state_id_ query parameters with .., /, or absolute path patterns (e.g., ?_state_id_=../../etc, ?_state_id_=/etc/passwd)._state_id_ values; server-side shiny.bookmark._restore_state logger warnings such as "Could not restore bookmarked state" triggered by invalid bookmark IDs.shiny_bookmarks/ directory by the web server process; access timestamps updated on sensitive files (e.g., configuration files, credential stores) not normally accessed by the Shiny process.shiny_bookmarks/ folder, observable via auditd or similar host-based monitoring (GitHub Advisory, Fix Commit).The primary remediation is to upgrade Shiny for Python to version 1.6.4 or later using pip install --upgrade shiny. The fix validates bookmark IDs against the allowlist regex [A-Za-z0-9_-]+ (a single safe path segment), gates restore logic on the application's bookmark_store setting, and prevents symlink-following in file-input restore. For deployments that cannot upgrade immediately, the only effective workaround is to strip the _state_id_ query parameter from all incoming requests at a reverse proxy or load balancer — no application-level configuration (including setting bookmark_store="disable") mitigates the issue on affected versions. Disabling bookmarking functionality entirely at the proxy level is recommended as a temporary measure (GitHub Advisory, py-shiny Release).
The vulnerability was reported by security researcher @0xRenSec and disclosed via the GitHub Security Advisory program. The advisory was published by Shiny maintainer @schloerke on September 3, 2026, and made public on October 9, 2026. No significant broader media coverage or notable community commentary beyond the standard advisory channels has been identified (GitHub Advisory, py-shiny Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."