PT-2024-22428 · Greykite · Greykite

Published

2024-03-14

·

Updated

2025-09-18

·

CVE-2024-28425

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions greykite version 1.0.0
Description The issue allows attackers to execute arbitrary code via uploading a crafted file, exploiting an arbitrary file upload vulnerability in the load obj function at /templates/pickle utils.py.
Recommendations For greykite version 1.0.0, consider disabling the load obj function at /templates/pickle utils.py until a patch is available to prevent exploitation of the arbitrary file upload vulnerability. Restrict access to the /templates/pickle utils.py module to minimize the risk of exploitation. Avoid using the vulnerable function to load objects from untrusted sources until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-28425
PYSEC-2024-276

Affected Products

Greykite