{"id":"CVE-2023-5245","aliases":["GHSA-897x-xvj8-42rq"],"url":"https://o3.security/vulnerability/CVE-2023-5245","summary":"Using MLeap for loading a saved model (zip archive) can lead to path traversal/arbitrary file creation and possibly remote code execution.","details":"FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory.\n\nWhen creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract().\n\nArbitrary file creation can directly lead to code execution","published":"2023-11-15T12:52:18.656Z","modified":"2026-08-12T03:51:23.255225694Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01186,"percentile":0.65003,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"ml.combust.mleap:mleap-runtime_2.12","fixedVersion":"0.23.1"}],"fix":{"url":"https://github.com/combust/mleap/pull/866#issuecomment-1738032225","label":"combust/mleap#866"},"references":[{"type":"WEB","url":"https://mvnrepository.com"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5245.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5245"},{"type":"ADVISORY","url":"https://research.jfrog.com/vulnerabilities/mleap-path-traversal-rce-xray-532656/"},{"type":"FIX","url":"https://github.com/combust/mleap/pull/866#issuecomment-1738032225"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:23.255225694Z"}}