Shamefile has an arbitrary file read via shamefile.yaml in shame next
Published Jul 20, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.18%
Description
Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose contents of files outside the repository, one line at a time, to the terminal of a user who runs the command. See patch commit for technical details. The issue is fixed in 0.1.7. Upgrade to either 0.1.7 or later versions to incorporate the patch. As a workaround, do not run `shame next` against untrusted `shamefile.yaml`. Use `shame me --dry-run` for CI validation.
Affected products
-
- Version < 0.1.7StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
shamefile
PyPI
Introduced 0 Fixed 0.1.7shamefile
npm
Introduced 0 Fixed 0.1.7shamefile
crates.io
Introduced 0 Fixed 0.1.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| PyPI | shamefile | 0 | 0.1.7 |
| npm | shamefile | 0 | 0.1.7 |
| crates.io | shamefile | 0 | 0.1.7 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 22, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.18% (0.00184) | 7.16th | v5 (v2026.06.15) |
| Jul 21, 2026 | 0.15% (0.00146) | 4.28th | v5 (v2026.06.15) |
| Jun 12, 2026 | 0.01% (0.00013) | 2.25th | v4 (v2025.03.14) |
References (7)
- https://github.com/BKDDFS/shamefile/commit/77b0aeea318503582818c708518c601fedc43557 x_refsource_MISC
- https://github.com/BKDDFS/shamefile/pull/80 x_refsource_MISC
- https://github.com/BKDDFS/shamefile/releases/tag/v0.1.7 x_refsource_MISC
- https://github.com/BKDDFS/shamefile/security/advisories/GHSA-x6p3-76f2-xxvh x_refsource_CONFIRM
- https://github.com/advisories/GHSA-x6p3-76f2-xxvh Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/shamefile/PYSEC-2026-3065.yaml x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-47144
| Link | Providers | Tags |
|---|---|---|
| https://github.com/BKDDFS/shamefile/commit/77b0aeea318503582818c708518c601fedc43557 | x_refsource_MISC | |
| https://github.com/BKDDFS/shamefile/pull/80 | x_refsource_MISC | |
| https://github.com/BKDDFS/shamefile/releases/tag/v0.1.7 | x_refsource_MISC | |
| https://github.com/BKDDFS/shamefile/security/advisories/GHSA-x6p3-76f2-xxvh | x_refsource_CONFIRM | |
| https://github.com/advisories/GHSA-x6p3-76f2-xxvh | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/shamefile/PYSEC-2026-3065.yaml | x_refsource_MISC | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-47144 |
Change history (0)
No recorded changes yet.