CVE-2026-33076: Python Path Traversal Fstring Host Param Unvalidated

A function builds a filesystem path (or path-like string later passed to open()/os.system()) by f-string interpolating a host/IP/server-style parameter without first validating it (e.g. via an `is_ip_or_dns`-style check that reassigns the parameter, or a pydantic IPvAnyAddress/DomainName typed parameter). Attacker controlled traversal sequences (e.g. `..`) i

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-33076-python-path-traversal-fstring-host-param-unvalidated --engine opengrep

Description

A function builds a filesystem path (or path-like string later passed to open()/os.system()) by f-string interpolating a host/IP/server-style parameter without first validating it (e.g. via an `is_ip_or_dns`-style check that reassigns the parameter, or a pydantic IPvAnyAddress/DomainName typed parameter). Attacker controlled traversal sequences (e.g. `..`) i