CVE-2023-29159: Encode Starlette

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.

Affected products

  • Encode Starlette: from 0.13.5, before 0.27.0 (fixed in 0.27.0)

Published 2023-06-01. Last modified 2026-06-17.