facebookresearch / facebookresearch/sam-3d-objects

vulnerability in sam-3d-objects project

Open
#90 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
7.4k
Forks
878
PR merge metrics
No merged PRs in 30d

Description

While working on sam-3d-objects project, I identified a vulnerability related to [CVE-2025-66221](https://vulert.com/vuln-db/CVE-2025-66221) in the safe_join() function of Werkzeug. The function allows Windows special device names (such as CON, AUX, etc.) to pass through path validation.

[CVE Report](https://vulert.com/vuln-scan/list/063c8bb0-1868-449b-b4b1-5b378ed95962)
[CVE Link](https://vulert.com/vuln-db/CVE-2025-66221)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.