Picard Project maintains a focused music tagging and metadata application that processes file metadata across a range of audio formats, creating exposure to path-traversal conditions in directory handling. The recurring weakness class reflects the challenges of safely validating and constraining file-access paths when ingesting external or user-supplied metadata. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Picard Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16194HIGH picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | Jun 7, 2018 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Picard Project.
Media articles that mention a CVE ID that affects a product developed by Picard Project — matched by CVE ID, not by vendor name.