The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.
"https://github.com/pypa/advisory-database/blob/main/vulns/radicale/PYSEC-2016-36.yaml"