HIGH🇵🇱 Wersja polska

CVE-2025-8406

CVSS 7.8v3.1pub. 2025-10-05upd. 2025-10-30

ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_directory` to validate files during `data.tar.gz` extraction, which fails to effectively detect symbolic and hard links. This vulnerability can lead to arbitrary file writes, potentially resulting in arbitrary command execution if critical files are overwritten.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Zenml

    APP
    Zenml
    0.83.1 – 0.84.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2024-2083CRITICAL9.9PL ✓same product

Path Traversal w ZenML – odczyt dowolnych plików przez endpoint /api/v1/steps

CVE-2024-9340HIGH7.5same product

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to c...

CVE-2024-4680HIGH8.8same product

A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session ...

CVE-2024-28424HIGH8.8same product

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materi...

CVE-2024-25723HIGH8.8same product

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation...