<!-- LLM_VERSION_INFO
FORMAT: text/markdown
CONTENT_TYPE: article
ORIGINAL_URL: https://streamlit.io/advisories/streamlit-security-advisory-2024-08-07
ALTERNATE_VERSION: advisories/streamlit-security-advisory-2024-08-07/index.html (text/html)
EXTRACTION_DATE: 2026-04-17T00:48:38.174Z

This is the markdown version with text-only content (images converted to alt-text).
For rich formatting with images, request the HTML version at: advisories/streamlit-security-advisory-2024-08-07/index.html
-->

# Streamlit Security Advisory

|     |
| --- |
| **CVSSv3 range:** [5.9](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N) |
| **Issue date:** 7 August 2024 |
| **CVE(S):** TBD (Will update when received from NVD) |

## 1. Impacted Products

Streamlit Open Source versions before 1.37.0.

## 2. Introduction

Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. The vulnerability was patched on Jul 25, 2024, as part of Streamlit open source version 1.37.0. The vulnerability only affects Windows.

## 3. Path Traversal Vulnerability

### 3.1 Description

On May 12, 2024, Streamlit was informed via our bug bounty program about a path traversal vulnerability in the open source library. We fixed and merged a patch remediating the vulnerability on Jul 25, 2024. The issue was determined to be in the moderate severity range with a maximum CVSSv3 base score of 5.9.

### 3.2 Scenarios and attack vector(s)

Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the [static file sharing](https://docs.streamlit.io/develop/concepts/configuration/serving-static-files) feature is enabled. An attacker could utilize the vulnerability to leak the password hash of the Windows user running Streamlit.

### 3.3 Resolution

The vulnerability has been fixed in all Streamlit versions released since Jul 25, 2024. We recommend all users upgrade to Version 1.37.0.

## 4. Contact

Please contact [security@snowflake.com](mailto:security@snowflake.com) if you have any questions regarding this advisory. If you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our [Vulnerability Disclosure Policy](https://hackerone.com/snowflake?type=team).
