GHSA-64hm-gfwq-jppw
HIGHCVE-2026-33166The Allure report generator is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or .plist) that points an attachment source to a sensitive file on the host system. During report generation, Allure will resolve these paths and include the sensitive files in the final report.
- Affected
- <= 2.37.0
- Fixed in
- 2.38.0
- Weakness
- CWE-22
- Published
- 2026-03-18
- Source
- github