{"id":"CVE-2024-12216","aliases":["PYSEC-2026-1406"],"url":"https://o3.security/vulnerability/CVE-2024-12216","summary":"GluonCV Arbitrary File Write via TarSlip","details":"A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from URLs without proper sanitization, making it susceptible to a TarSlip vulnerability. Attackers can exploit this by crafting malicious tar files that, when extracted, can overwrite files on the victim's system via path traversal or faked symlinks.","published":"2025-03-20T12:32:42Z","modified":"2026-07-07T17:57:24.443864061Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},"epss":{"score":0.00306,"percentile":0.23421,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"gluoncv","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12216"},{"type":"PACKAGE","url":"https://github.com/dmlc/gluon-cv"},{"type":"WEB","url":"https://github.com/dmlc/gluon-cv/blob/3862e2db33ab650eff7c7c5c5891e805207027b1/gluoncv/utils/filesystem.py#L223-L229"},{"type":"WEB","url":"https://huntr.com/bounties/46081fdc-2951-4deb-a2c9-2627007bdce0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:24.443864061Z"}}