-
CVSS Score
-The vulnerability description explicitly states the 'runs/delete-batch' endpoint fails to mitigate path traversal when processing user-controlled 'run-names'. While no exact code is shown, in web service architectures: 1) Endpoint handlers typically map directly to view functions 2) File operations using unsanitized user input would occur in these handlers 3) The CWE-23 classification confirms relative path traversal. The combination of these factors strongly indicates the endpoint handler function is the vulnerable component.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| aim | pip |
Ongoing coverage of React2Shell