CVE-2026-47144

MEDIUM

Shamefile has an arbitrary file read via shamefile.yaml in shame next

Title source: cna
STIX 2.1

Description

Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose contents of files outside the repository, one line at a time, to the terminal of a user who runs the command. See patch commit for technical details. The issue is fixed in 0.1.7. Upgrade to either 0.1.7 or later versions to incorporate the patch. As a workaround, do not run `shame next` against untrusted `shamefile.yaml`. Use `shame me --dry-run` for CI validation.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (4)
BKDDFS/shamefile < 0.1.7
crates.io/shamefile 0 - 0.1.7crates.io
npm/shamefile 0 - 0.1.7npm
pypi/shamefile 0 - 0.1.7PyPI
Published Jul 20, 2026
Tracked Since Jul 21, 2026