CVE-2026-44018: Insecure Urljoin To Path

Passing the result of `urljoin` directly into a `Path` object without validation can result in Path Traversal or Local File Inclusion (LFI). Python's `urljoin` ignores the base URI entirely if the target substring provides an absolute path or wrapper scheme. This allows attackers to specify arbitrary local paths out-of-bounds.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-44018-insecure-urljoin-to-path --engine opengrep

Description

Passing the result of `urljoin` directly into a `Path` object without validation can result in Path Traversal or Local File Inclusion (LFI). Python's `urljoin` ignores the base URI entirely if the target substring provides an absolute path or wrapper scheme. This allows attackers to specify arbitrary local paths out-of-bounds.