CVE-2024-12216
CVSS 3.0 Score 7.1 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 20
Summary
CVE-2024-12216 is a newly disclosed vulnerability affecting the `ImageClassificationDataset.from_csv()` API in the `dmlc/gluon-cv` library, version 0.10.0. This issue enables arbitrary file write through a TarSlip vulnerability. The function downloads and extracts `tar.gz` files from unverified URLs without proper sanitization, leaving the system susceptible to attacks. Malicious actors can create crafted tar files that, upon extraction, overwrite sensitive files on the victim's system through path traversal or faked symlinks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.