Summary
CVE-2026-75111 is a path traversal vulnerability in Evidently AI’s evidently Python package (Evidently UI) that allows unauthenticated attackers to read arbitrary files from the host filesystem outside the intended workspace directory. The flaw resides in the dataset materialization endpoint and affects all versions through 0.7.21. It is rated HIGH severity, with a CVSS v4.0 base score of 8.7.
Technical details
- Root cause: the
POST /api/datasets/materializeendpoint (backed byFileDataSourceinsrc/evidently/ui/service/datasets/data_source.py) accepts a user-suppliedfilenameparameter and passes it directly toposixpath.join()without any containment validation. posixpath.join()honors both relative traversal sequences (../../../etc/passwd) and absolute paths, allowing the resulting path to escape the configured workspace directory.- Trigger conditions: the endpoint is reachable over the network and, in the default configuration where authentication is disabled, requires no credentials or user interaction to exploit.
- Impact: an attacker can materialize arbitrary
.csv/.parquet-readable files from the server filesystem into a dataset and retrieve them, potentially exfiltrating sensitive data such as credentials, database exports, or training data stored anywhere on the host.
Affected software
- Evidently (PyPI package
evidently) — Evidently UI, versions 0 through 0.7.21
Severity
- CVSS v4.0: 8.7 (HIGH) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1: 7.5 (HIGH) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: no patched release has been published for this issue as of this writing; monitor the
evidentlyai/evidentlyGitHub repository and PyPI for a fixed release beyond 0.7.21 and upgrade as soon as one is available. - If no patch: do not expose the Evidently UI dataset materialization endpoint to untrusted networks; enable authentication on the Evidently UI service (it is disabled by default); restrict network access to the service to trusted hosts only; and consider running the service with a restricted filesystem user/container so any file read is limited in scope.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Evidently - ML Monitoring Demo

