PT-2025-4075 · Unknown · Deepjavalibrary

Siddvenk

·

Published

2025-01-29

·

Updated

2025-10-14

·

CVE-2025-0851

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deep Java Library (DJL) versions 0.1.0 through 0.31.0
Description A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations. This issue exists due to the lack of protection against absolute path traversal during the extraction process of tar and zip model archives. The issue can be exploited when extracting archives created on different operating systems, allowing an attacker to write artifacts outside the intended destination.
Recommendations For versions 0.1.0 through 0.31.0, update to version 0.31.1 or later to resolve the issue. As a temporary workaround, do not use model archive files from sources you do not trust, and only use model archives from official sources like the DJL Model Zoo, or models that you have created and packaged yourself.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-01109
CVE-2025-0851
GHSA-JCRP-X7W3-FFMG

Affected Products

Deepjavalibrary