facebookresearch / facebookresearch/sam-3d-objects
vulnerability in sam-3d-objects project
Open
- Dominant language
- Python
- Stars
- 7.4k
- Forks
- 878
- PR merge metrics
- No merged PRs in 30d
Description
While working on sam-3d-objects project, I identified a vulnerability related to [CVE-2025-66221](https://vulert.com/vuln-db/CVE-2025-66221) in the safe_join() function of Werkzeug. The function allows Windows special device names (such as CON, AUX, etc.) to pass through path validation.
[CVE Report](https://vulert.com/vuln-scan/list/063c8bb0-1868-449b-b4b1-5b378ed95962)
[CVE Link](https://vulert.com/vuln-db/CVE-2025-66221)
Contributor guide
Assessment
This issue has not been assessed yet.