CVE-2021-41131 is a path traversal vulnerability in python-tuf, the Python reference implementation of The Update Framework (TUF), affecting both its client implementations. This flaw allows an attacker to overwrite .json files anywhere on a client system by manipulating rolenames in delegated targets metadata. The vulnerability carries a high severity CVSS score of 8.7, indicating a network-based attack with high impact on integrity and availability, though it requires specific conditions for exploitation, such as arbitrary rolename selection and the ability to insert and delegate malicious metadata. While a fix is available in version 0.19+, there are no practical workarounds without modifying the python-tuf code. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.18.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:the_update_framework:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.