HIGHPyPI

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

CVE-2025-51481Published 1 year agoUpdated 6 days agoSource: OSV

Affected packages

  • dagster-geall versions

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.52%
EPSS percentile
41.5%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 42%.

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC | HackTribune