Voila 0.2.17, 0.3.8, 0.4.4, 0.5.6 security update out (CVE-2024-30265)

4 releases of Voila that fix an issue allowing users to access any file on the server. CVE-2024-30265

This security breach should only affect users of the voila CLI, if voila is used as a server extension you should be fine.

Update recommended!

pip install --upgrade voila
5 Likes

GHSA: Local file inclusion in voilà-dashboard · Advisory · voila-dashboards/voila · GitHub