


Perceptive Security
SOC/SIEM Consultancy

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Sl…
Published:
16 April 2026 at 22:00:00
Alert date:
17 April 2026 at 23:02:26
Source:
nvd.nist.gov
Web Technologies
The Gramps Web API, a Python REST API for genealogical research software, contains a path traversal vulnerability (Zip Slip) in versions 1.6.0 through 3.11.0. The vulnerability exists in the media archive import feature where authenticated users with owner-level privileges can craft malicious ZIP files with directory-traversal filenames. This allows attackers to write arbitrary files outside the intended temporary extraction directory on the server's local filesystem. The issue has been patched in version 3.11.1 by implementing validation of ZIP entry names against the resolved real path of the temporary directory before extraction.
Technical details
Mitigation steps:
Affected products:
Gramps Web API
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40258
https://github.com/gramps-project/gramps-web-api/commit/3ed4342711e3ec849552df09b1fe2fbf2ca5c29a
https://github.com/gramps-project/gramps-web-api/releases/tag/v3.11.1
https://github.com/gramps-project/gramps-web-api/security/advisories/GHSA-m5gr-86j6-99jp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
