HIGH 8.7 NVD

CVE-2026-75111

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary fil

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.

References

Published: 2026-08-17 · Source: NVD · Feed updated: 2026-08-18
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-17 via NVD.
vulnfeed aggregates 11051 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.