CVE-2026-42351: pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
A raw string path concatenation vulnerability in pygeoapi’s STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in configuration.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42351 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →