CVE-2025-0851

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 29, 2025
CWE ID 73
CWE ID 36

Summary

CVE-2025-0851 is a newly disclosed vulnerability affecting the ZipUtils.unzip and TarUtils.untar functions in the Deep Java Library (DJL). This issue enables an attacker to traverse file paths arbitrarily, potentially allowing them to write files to locations of their choice. By manipulating the input given to these functions, a malicious actor can bypass intended access restrictions and create or overwrite critical system files. This can lead to serious consequences, including data theft, system compromise, or denial of service. It is crucial that users update their DJL installations to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share