Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| sanic(PyPI) | 22.0.0 | 22.6.1 | N/A |
| sanic(PyPI) | 21.0.0 | 21.12.2 | N/A |
| sanic(PyPI) | 0 | 20.12.7 | N/A |
CVSS Metrics