The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
https://github.com/advisories/GHSA-687h-86vc-5x59
https://github.com/github/securitylab/issues/669#issuecomment-1117265726