voila
Voilà turns Jupyter notebooks into standalone web applications
Activity
- Latest release
- 1w ago
- Total releases
- 115
- Cadence
- ~11 days
- Last 12 months
- 2
Reach
- Stars
- 5.9k
Details
- License
- custom
- First release
- Aug 08, 2018
| Version | Released | |
|---|---|---|
0.5.13
patch
| ||
0.5.12
patch
| ||
0.5.11
patch
| ||
0.5.10
patch
| ||
0.5.9
patch
| ||
0.5.8
patch
| ||
0.4.6
patch
| ||
0.4.5
patch
| ||
0.5.7
patch
| ||
0.2.17
patch
| ||
0.3.8
patch
| ||
0.4.4
patch
| ||
0.5.6
patch
| ||
0.5.5
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.4
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.3
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.2
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0rc0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0b1
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0b0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0a5
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.7
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0a4
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0a3
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0a2
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0a1
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0a0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0rc1
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0rc0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0b0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0a2
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0a1
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0a0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.6
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.5
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.4
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.3
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0rc0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0b0
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0a2
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0a1
pre
1 CVE
CVE-2024-30265
PYSEC-2026-2027
GHSA-2q59-h24c-w6fg
Jul 07, 2026
Voilà Local file inclusion
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactAny deployment of voilà dashboard allow local file inclusion, that is to say any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. PatchesThis is patched in 0.2.17+, 0.3.8+, 0.4.4+, 0.5.6+ WorkaroundsNone. ReferencesCWE-73: External Control of File Name or Path Original reportI have found a local file inclusion vulnerability in one of your subprojects, voila (https://github.com/voila-dashboards/voila). The vulnerability exists in the "/static" Route, and can be exploited by simply making a request such as this:
...or by using a webbrowser to download the file. I dug into the source code, and I think the offending line is here: https://github.com/voila-dashboards/voila/blob/8419cc7d79c0bb1dabfbd9ec49cb957740609d4d/voila/app.py#L664
I suspect this was an oversight during development. Setting I have found multiple voila instances online that are impacted, such as:
...but many more probably exist. They're easy to identify by Affected versions
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 88 more Show less
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.18.post1
0.1.19
0.1.2
0.1.20
0.1.21
0.1.22
0.1.23
0.1.24
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.0a0
0.3.0a1
0.3.0a2
0.3.0b0
0.3.0rc0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.0a0
0.4.0a1
0.4.0a2
0.4.0b0
0.4.0rc0
0.4.0rc1
0.4.1
0.4.2
0.4.3
0.5.0
0.5.0a0
0.5.0a1
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0b0
0.5.0b1
0.5.0rc0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
Fixed in
0.2.17
0.3.8
0.4.4
0.5.6
References
Updated Jul 07, 2026 · Source: OSV.dev |