CVE-2026-33054: Pathlib Path Traversal Unvalidated Token Concat

A user-controlled string is concatenated with a path prefix and joined to a base directory using pathlib without validation. A value containing '..' segments resolves outside the base directory, enabling arbitrary file read/write/delete (CWE-22 / Path Traversal, CVE-2026-33054). Mitigation: (1) validate the input against an allowlist regex such as r'^[A-Za-z

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-33054-pathlib-path-traversal-unvalidated-token-concat --engine opengrep

Description

A user-controlled string is concatenated with a path prefix and joined to a base directory using pathlib without validation. A value containing '..' segments resolves outside the base directory, enabling arbitrary file read/write/delete (CWE-22 / Path Traversal, CVE-2026-33054). Mitigation: (1) validate the input against an allowlist regex such as r'^[A-Za-z