CVE-2026-85183
- EPSS 0.15%
- Veröffentlicht 03.09.2026 14:12:21
- Zuletzt bearbeitet 10.09.2026 15:53:23
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains an...
CVE-2026-48544
- EPSS 0.41%
- Veröffentlicht 27.05.2026 15:16:30
- Zuletzt bearbeitet 14.07.2026 22:17:03
Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended module directory by exploiting an...
CVE-2024-47833
- EPSS 0.25%
- Veröffentlicht 09.10.2024 19:15:14
- Zuletzt bearbeitet 16.10.2024 16:33:34
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed i...