{"id":"CVE-2024-8616","aliases":["PYSEC-2026-1441"],"url":"https://o3.security/vulnerability/CVE-2024-8616","summary":"H2O Vulnerable to Arbitrary File Overwrite","details":"In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controllable `mexport.dir` parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system.","published":"2025-03-20T12:32:48Z","modified":"2026-07-07T17:56:21.858937760Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"ai.h2o:h2o-core","fixedVersion":null},{"ecosystem":"PyPI","name":"h2o","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8616"},{"type":"PACKAGE","url":"https://github.com/h2oai/h2o-3"},{"type":"WEB","url":"https://github.com/h2oai/h2o-3/blob/088190f9d0370a02a483fca68d8dc89c996b4f83/h2o-core/src/main/java/water/api/ModelsHandler.java#L310"},{"type":"WEB","url":"https://huntr.com/bounties/aebf69a5-b9b1-4d2f-a8ff-902c11a8c97a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:21.858937760Z"}}