Overview
jaraco.context Has a Path Traversal Vulnerability
Advisory
Affected versions of the jaraco.context package are vulnerable to Path Traversal due to improper path sanitization.
How to Fix
Upgrade
jaraco-context
to6.1.0
or higher.Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260114-26312/CVE-2026-23949
- https://data.safetycli.com/changelogs/jaraco.context/
- https://github.com/advisories/GHSA-58pv-8j8x-9vj2
- https://pypi.org/project/jaraco.context
- https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2
- https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9
- https://nvd.nist.gov/vuln/detail/CVE-2026-23949
- https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91
- https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76
- https://github.com/advisories/GHSA-58pv-8j8x-9vj2
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
