Ganga Project is a workflow and job management framework used in high-energy physics research environments, with a narrow product footprint centered on the Ganga tool itself. The observed vulnerability pattern reflects file-handling exposure through path-traversal weaknesses, a class common to tools that interact with user-supplied file paths and directories in research-oriented workflows.
The number and severity of CVEs published that impact products developed by Ganga Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31507CRITICAL The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | Jul 11, 2022 | 9.3 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ganga Project.
Media articles that mention a CVE ID that affects a product developed by Ganga Project — matched by CVE ID, not by vendor name.