Skip to content

Request CVE-ID and GitHub Security Advisory for Fixed Path Traversal Vulnerability (VULN-183589) #574

@g0w6y

Description

@g0w6y

Hi Team,

I am the security researcher who reported the path traversal vulnerability in mssql-python.

Report Details:

  • Submitted to MSRC on April 20, 2026 (VULN-183589, Case 113816)
  • CWE: CWE-22 (Path Traversal)
  • CVSS v3.1: 7.5 High (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L)

Vulnerability:
The setup_logging(log_file_path=...) function only performed an extension check and was vulnerable to directory traversal, allowing arbitrary file writes.

Fix:

The issue is now resolved.

Request:
I kindly request the maintainers to:

  1. Create a GitHub Security Advisory for this vulnerability.
  2. Request a CVE-ID from MITRE.

Assigning a CVE will help with proper tracking by vulnerability scanners, Linux distributions, and the broader security community.

Thank you for your time and for merging the fix quickly.

Best regards,
Gouri Sankar A

Metadata

Metadata

Assignees

No one assigned

    Labels

    triage neededFor new issues, not triaged yet.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions