CVE-2026-39847
The RSGI static handler for Emmett's internal assets (/emmett paths) is vulnerable to path traversal attacks.
An attacker can use ../ sequences (eg /emmett/../rsgi/handlers.py) to read arbitrary files outside the assets directory.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/emmett-framework/emmett/security/advisories/GHSA-pr46-2v3c-5356, https://nvd.nist.gov/vuln/detail/CVE-2026-39847, https://github.com/emmett-framework/emmett, https://github.com/pypa/advisory-database/tree/main/vulns/emmett/PYSEC-2026-59.yaml
