CVE-2026-33166 is a high-severity (CVSS 8.6) path traversal vulnerability affecting Allure Report generator versions prior to 2.38.0. An unauthenticated attacker can exploit this with low complexity by crafting malicious test result files, enabling arbitrary sensitive file reading from the host system during report generation. This could lead to significant information disclosure. Currently, there is no evidence of active exploitation or public exploit code, though it has garnered minor community discussion. Users are advised to upgrade to Allure Report version 2.38.0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.38.0CPE matchmatch criteria | cpe:2.3:a:qameta:allure_report:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.