CVE-2026-40576: Python Path Traversal Unsafe Sandbox Resolver

Path-resolution helper fails to enforce its sandbox boundary. The function either (a) short-circuits and returns a caller-supplied absolute path verbatim, or (b) joins a base directory with a caller-controlled filename and returns the result without resolving with `os.path.realpath` and verifying containment (e.g. via `os.path.commonpath`, `startswith`, or `

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-40576-python-path-traversal-unsafe-sandbox-resolver --engine opengrep

Description

Path-resolution helper fails to enforce its sandbox boundary. The function either (a) short-circuits and returns a caller-supplied absolute path verbatim, or (b) joins a base directory with a caller-controlled filename and returns the result without resolving with `os.path.realpath` and verifying containment (e.g. via `os.path.commonpath`, `startswith`, or `