PatchSiren

posit-dev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM posit-dev CVE published 2026-10-09

CVE-2026-108258

CVE-2026-108258 debrief based on the supplied source corpus. The CVE record was published on 2026-10-09T20:56:37.000Z and has not been modified since then. Shiny for Python's bookmark-restore feature is vulnerable to path traversal. A client-supplied `_state_id_` query-string value is joined into the server-side bookmark directory without validation, allowing an attacker to probe for the existence and JSO [truncated]