RStudio's vulnerability footprint centers on its data-science platform products, primarily Connect and Shiny Server, which are widely used for hosting and sharing R-based analytical applications. The durable signal reflects application-layer input-handling weaknesses, notably path traversal and open-redirect flaws, that recur across its web-facing deployment model. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rstudio over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3374MEDIUM Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash. | Apr 2, 2021 | 5.3 | 35 | NO | YES |
CVE-2022-38131MEDIUM RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites. | Sep 6, 2022 | 6.1 | 31 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rstudio.
Media articles that mention a CVE ID that affects a product developed by Rstudio — matched by CVE ID, not by vendor name.