Directory traversal vulnerability in Aspen prior to 0.22 allows remote malicious users to read arbitrary files via a .. (dot dot) to the default URI.
aspen aspen