Database/AI/ML frameworks & serving
Keras (`utils.get_file`, tar extract): Path traversal on tar extraction
CVSS 8.9CVE-2025-12060AI/ML frameworks & servingcurated
Impact
Path traversal on tar extraction → arbitrary file write
Who can reach it
Customer-supplied dataset/model URL fetched with extract=True
What to do
Upgrade; a training job with write access to shared mounts can escape into other tenants' paths if mounts are shared
References
Related entries
- llama.cpp (`gguf_init_from_file_impl`): Integer overflow in GGUF initCVE-2025-53630 · llama.cpp (`gguf_init_from_file_impl`)High
- Pure Storage FlashArray VASA provider: A vSphere or ESXi administrator with VASA access to a FlashArray escalates toCVE-2023-36628 · Pure Storage FlashArray VASA providerHigh
- LangChain (recursive URL loader): SSRF — crawling proceeds to internal hostsCVE-2023-46229 · LangChain (recursive URL loader)High
- llama.cpp / GGUF library: Heap buffer overflow in GGUF `infoCVE-2024-21802 · llama.cpp / GGUF libraryHigh
- llama.cpp / GGUF: Heap overflow in `GGUF_TYPE_ARRAY`/`GGUF_TYPE_STRING` parsingCVE-2024-21825 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `header.n_tensors` handlingCVE-2024-21836 · llama.cpp / GGUFHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.