Paste
Tools for using a Web Server Gateway Interface stack
Activity
- Latest release
- 2y ago
- Total releases
- 76
- Cadence
- ~20 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Oct 03, 2005
| Version | Released | |
|---|---|---|
3.10.1
patch
| ||
3.10.0
minor
| ||
3.9.0
minor
| ||
3.8.0
minor
| ||
3.7.1
minor
| ||
3.6.1
patch
| ||
3.6.0
minor
| ||
3.5.3
patch
| ||
3.5.2
patch
| ||
3.5.1
patch
| ||
3.5.0
minor
| ||
3.4.6
patch
| ||
3.4.5
patch
| ||
3.4.4
patch
| ||
3.4.3
patch
| ||
3.4.2
patch
| ||
3.4.1
patch
| ||
3.4.0
minor
| ||
3.3.0
minor
| ||
3.2.7
patch
| ||
3.2.6
patch
| ||
3.2.5
patch
| ||
3.2.4
patch
| ||
3.2.3
patch
| ||
3.2.2
patch
| ||
3.2.1
patch
| ||
3.2.0
minor
| ||
3.1.1
patch
| ||
3.1.0
minor
| ||
3.0.8
patch
| ||
3.0.7
patch
| ||
3.0.6
patch
| ||
3.0.5
patch
| ||
3.0.4
patch
| ||
3.0.3
patch
| ||
3.0.2
patch
| ||
3.0.1
patch
| ||
3.0.0
major
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0
major
| ||
1.7.5.1
patch
| ||
1.7.5
patch
1 CVE
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.4
patch
1 CVE
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.3.1
patch
2 CVEs
CVE-2010-2477
GHSA-7gfc-2v6g-6w9f
PYSEC-2010-29
May 17, 2022
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
Medium
Network
Low
None
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 19 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
Fixed in
1.7.4
References
Updated Oct 09, 2024 · Source: OSV.dev
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.3
patch
2 CVEs
CVE-2010-2477
GHSA-7gfc-2v6g-6w9f
PYSEC-2010-29
May 17, 2022
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
Medium
Network
Low
None
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 19 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
Fixed in
1.7.4
References
Updated Oct 09, 2024 · Source: OSV.dev
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.2
patch
2 CVEs
CVE-2010-2477
GHSA-7gfc-2v6g-6w9f
PYSEC-2010-29
May 17, 2022
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
Medium
Network
Low
None
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 19 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
Fixed in
1.7.4
References
Updated Oct 09, 2024 · Source: OSV.dev
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.1
patch
2 CVEs
CVE-2010-2477
GHSA-7gfc-2v6g-6w9f
PYSEC-2010-29
May 17, 2022
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
Medium
Network
Low
None
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 19 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
Fixed in
1.7.4
References
Updated Oct 09, 2024 · Source: OSV.dev
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7
minor
2 CVEs
CVE-2010-2477
GHSA-7gfc-2v6g-6w9f
PYSEC-2010-29
May 17, 2022
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
Medium
Network
Low
None
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 19 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
Fixed in
1.7.4
References
Updated Oct 09, 2024 · Source: OSV.dev
CVE-2012-0878
GHSA-27px-qpmj-qg38
PYSEC-2012-15
PYSEC-2026-2859
May 17, 2022
Paste Script has improper group memberships permissions
High
Network
Low
Low
None
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem. Affected versions
0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
+ 21 more Show less
0.9.8.1
1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1
1.7.4
1.7.5
Fixed in
1.7.5.1
References
Updated Jul 13, 2026 · Source: OSV.dev |