VendorsDagsterlabsdagster1.10.14
Vulnerabilities

Dagsterlabs Dagster 1.10.14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-51481
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
Published 2025-07-22 · Analyzed
6.6EPSS 0.005