An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Flask-Cors(PyPI) | 0 | 3.0.9 | N/A |
CVSS Metrics