facebookresearch / facebookresearch/sam-3d-objects
Vulnerability in sam-3d-objects project
Open
- Dominant language
- Python
- Stars
- 7.4k
- Forks
- 878
- PR merge metrics
- No merged PRs in 30d
Description
The Path Traversal vulnerability in **gdown** version **5.2.1** highlights the risks of extracting untrusted archives without proper filename validation. By allowing malicious ZIP or TAR files to write outside the intended directory, this flaw can lead to **arbitrary file overwrite** and, in some cases, even **remote code execution**.
[CVE Report](https://vulert.com/vuln-scan/list/89eb707e-a628-443f-8702-dbbdee0d699c?sort_order=desc&sort_by=created_at)
[CVE Link](https://vulert.com/vuln-db/gdown-affected-by-arbitrary-file-write-via-path-traversal-in-gdown-extractall)
Contributor guide
Assessment
This issue has not been assessed yet.