Loading HuntDB...

GHSA-87jx-4wq7-9wr5

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.

Related CVEs

Key Information

GHSA ID
GHSA-87jx-4wq7-9wr5
Published
May 1, 2022 1:47 AM
Last Modified
May 1, 2022 1:47 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 28, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.