CVE-2026-23535: Path Traversal From Untrusted Slug

Constructing a file path using a `.slug` attribute without sanitization can lead to path traversal vulnerabilities (CWE-22) if the attribute is untrusted or controlled by an external/compromised entity (e.g., an API server). Directory traversal sequences like '../' or absolute paths can escape the intended output directory. Always use sanitization functions

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-23535-path-traversal-from-untrusted-slug --engine opengrep

Description

Constructing a file path using a `.slug` attribute without sanitization can lead to path traversal vulnerabilities (CWE-22) if the attribute is untrusted or controlled by an external/compromised entity (e.g., an API server). Directory traversal sequences like '../' or absolute paths can escape the intended output directory. Always use sanitization functions