CVE-2025-0851
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-0851 is a newly disclosed vulnerability affecting the ZipUtils.unzip and TarUtils.untar functions in the Deep Java Library (DJL). This issue enables an attacker to traverse file paths arbitrarily, potentially allowing them to write files to locations of their choice. By manipulating the input given to these functions, a malicious actor can bypass intended access restrictions and create or overwrite critical system files. This can lead to serious consequences, including data theft, system compromise, or denial of service. It is crucial that users update their DJL installations to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.