CVE-2025-51481

medium

Description

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

References

https://www.gecko.security/blog/cve-2025-51481

https://github.com/dagster-io/dagster/pull/30002

https://github.com/dagster-io/dagster

Details

Source: Mitre, NVD

Published: 2025-07-22

Updated: 2025-07-25

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.6

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00011