← Back to browse · API

CVE-2025-0851

Severity
CRITICAL
CVSS
9.3
EPSS
0.23267
Risk score
45.34
CISA KEV
No
PoC
No
Published
2025-01-29
Modified
2025-10-14
First seen
2026-08-07
Aliases
EUVD-2025-0175, GHSA-JCRP-X7W3-FFMG
Products
aws:DeepJavaLibrary 0.1.0 <0.31.1
Sources
euvd EUVD-2025-0175

Description

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.

References