


Perceptive Security
SOC/SIEM Consultancy

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmet…
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 23:01:57
Source:
nvd.nist.gov
Web Technologies
CVE-2026-39847 affects the Emmett full-stack Python web framework versions 2.5.0 to before 2.8.1. The vulnerability exists in the RSGI static handler for Emmett's internal assets, specifically paths beginning with /__emmett__. Attackers can exploit this by using path traversal sequences like ../ to read arbitrary files outside the intended assets directory. An example attack vector is /__emmett__/../rsgi/handlers.py which allows unauthorized file access. This security flaw has been patched in version 2.8.1.
Technical details
Mitigation steps:
Affected products:
Emmett Python web framework
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39847
https://github.com/emmett-framework/emmett/security/advisories/GHSA-pr46-2v3c-5356
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
