Security Advisory

CVE-2025-51481

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-22 00:00:00
Last updated 2025-07-22 18:13:15
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.