PT-2025-38714 · Txtai · Txtai

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-10854

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions txtai (affected versions not specified)
Description The txtai framework permits loading compressed tar files as embedding indices. The validate function, designed to prevent path traversal, does not account for symbolic links within these tar files. This allows an attacker to write files to arbitrary locations on the filesystem when loading untrusted embedding indices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-10854

Affected Products

Txtai