Description
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
Published: 2025-07-22
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-22342 Dagster Local File Inclusion vulnerability
Github GHSA Github GHSA GHSA-h7x8-jv97-fvvm Dagster Local File Inclusion vulnerability
History

Tue, 07 Oct 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dagsterlabs
Dagsterlabs dagster
CPEs cpe:2.3:a:dagsterlabs:dagster:1.10.14:*:*:*:*:*:*:*
Vendors & Products Dagsterlabs
Dagsterlabs dagster

Tue, 22 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Description Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
References

Subscriptions

Dagsterlabs Dagster
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-07-22T18:13:15.486Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51481

cve-icon Vulnrichment

Updated: 2025-07-22T18:12:17.216Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-22T17:15:33.543

Modified: 2025-10-07T20:34:11.423

Link: CVE-2025-51481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses