THREAT OPS › Threat News › [NVD] CVE-2026-24486 (HIGH 8.6) — Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on th
[NVD] CVE-2026-24486 (HIGH 8.6) — Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on th
CVE-2026-24486 CVSS: 8.6 HIGH Published: 2026-01-27T01:16:02.303
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users s
Indicators of compromise
- CVE-2026-24486cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-24486