HIGHPyPI →
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
Affected packages
- dagster-ge— all versions
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.52%
- EPSS percentile
- 41.5%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 42%.
Sources
- https://github.com/dagster-io/dagster/pull/30002
- https://github.com/dagster-io/dagster
- https://www.gecko.security/blog/cve-2025-51481
Structured record: https://osv.dev/vulnerability/PYSEC-2025-102
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta