MEDIUM
eghuzefa
CVE published 2026-04-28
CVE-2026-7214
A path traversal vulnerability was identified in engineer-your-data up to 0.1.3. The vulnerability affects the functions read_file/write_file/list_files/file_inf in src/server.py. The manipulation of the WORKSPACE_PATH argument leads to path traversal. The attack may be initiated remotely. The project was informed early through an issue report but has not responded yet.