{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/evidentlyai/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75111"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Evidently (0.7.21)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-75111","path-traversal","web-application"],"_cs_type":"advisory","_cs_vendors":["EvidentlyAI"],"content_html":"\u003cp\u003eEvidently versions 0.7.21 and earlier contain a critical path traversal vulnerability in the UI component. The flaw exists within the dataset materialization logic, specifically in the \u003ccode\u003efilename\u003c/code\u003e parameter, which lacks sufficient input validation. An unauthenticated attacker can supply crafted file paths, including directory traversal sequences (e.g., \u0026quot;../\u0026quot;) or absolute filesystem paths, to the dataset materialization endpoint.\u003c/p\u003e\n\u003cp\u003eWhen processed, the application attempts to access the specified file outside of the intended workspace directory. The resulting data is then materialized into a dataset, which the attacker can subsequently retrieve via the standard download functionality. This allows for the exfiltration of sensitive system files, configuration data, or other proprietary information accessible to the service process. The issue has been identified in the \u003ccode\u003edata_source.py\u003c/code\u003e module of the Evidently repository.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables unauthorized reading of arbitrary files on the host system. This could lead to the exposure of sensitive configuration files, environment variables, source code, or internal application data. Given the unauthenticated nature of the exploit, this vulnerability poses a significant risk to any publicly or internally accessible instances of the Evidently UI.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Evidently version 0.7.22 or later immediately to patch the validation logic in the dataset materialization endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Evidently UI service to trusted network segments, ideally requiring VPN or zero-trust authentication until the patch is applied.\u003c/li\u003e\n\u003cli\u003eDeploy the detection rule below to identify exploitation attempts targeting the dataset materialization endpoint.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious requests containing path traversal patterns (e.g., ../) targeting the \u003ccode\u003e/datasets/\u003c/code\u003e or materialization-related URI paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T22:51:40Z","date_published":"2026-08-17T22:51:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-evidently-path-traversal/","summary":"An unauthenticated path traversal vulnerability (CVE-2026-75111) in the Evidently UI dataset materialization endpoint allows attackers to read arbitrary files from the host system.","title":"Path Traversal Vulnerability in Evidently UI","url":"https://feed.craftedsignal.io/briefs/2026-08-evidently-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - EvidentlyAI","version":"https://jsonfeed.org/version/1.1"}