High Severity: dash-uploader Path Traversal Vulnerability
- Severity
- HIGH
- Affected component
- dash-uploader (pypi)
- Affected versions
- >= 0.1.0, <= 0.7.0a2 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.7.0a1, <= 0.7.0a1 or >= 0.7.0a2, <= 0.7.0a2 or >= 0.1.0, <= 0.7.0a2 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.7.0a1, <= 0.7.0a1 or >= 0.7.0a2, <= 0.7.0a2 or >= 0.1.0, < 0.7.0a1 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.3, <= 0.2.3 or >= 0.2.4, <= 0.2.4 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.4.2, <= 0.4.2 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1
- Patched version
- Not yet available
An unauthenticated path traversal vulnerability has been reported in dash-uploader versions 0.1.0 through 0.7.0a2, potentially allowing remote code execution.
What happened
An unauthenticated path traversal vulnerability has been identified in dash-uploader versions 0.1.0 through 0.7.0a2. This vulnerability could allow an attacker to execute arbitrary code remotely. The issue was first flagged on May 8, 2026. Currently, no patched version of dash-uploader is available.
Users of dash-uploader should assess their exposure by checking if their applications are using any version within the affected range. It is recommended to replace dash-uploader with an alternative file-upload component or apply temporary mitigations while a replacement is deployed.
What to do about it
- Identify and inventory all instances of dash-uploader in your software.
- Replace dash-uploader with an alternative file-upload component.
- Apply temporary mitigations to restrict access to dash-uploader endpoints if replacement is not immediately feasible.
- Monitor the primary sources for updates on a potential patch.
- Ensure that all instances of dash-uploader are secured or replaced as soon as possible.
How 0Day would have caught this
dash-uploader is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using dash-uploader versions 0.1.0 through 0.7.0a2.
What should I do right now?
Replace dash-uploader with an alternative file-upload component or apply temporary mitigations while a replacement is deployed.
Is there a patched version available?
No official fix has been published yet. Monitor the sources for updates.