{"id":"CVE-2021-41127","aliases":["GHSA-4365-fhm5-qcrx","PYSEC-2021-381"],"title":"Maliciously Crafted Model Archive Can Lead To Arbitrary File Write","summary":"Maliciously Crafted Model Archive Can Lead To Arbitrary File Write","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H","vendor":"rasa","product":"rasa","ecosystem":"pip","affected":["rasa < 2.8.10"],"patched":["rasa 2.8.10"],"published":"2021-10-22","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4365-fhm5-qcrx","references":[{"url":"https://github.com/RasaHQ/rasa/security/advisories/GHSA-4365-fhm5-qcrx"},{"url":"https://github.com/RasaHQ/rasa/commit/1b6b502f52d73b4f8cd1959ce724b8ad0eb33989"},{"url":"https://github.com/RasaHQ/rasa"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/rasa/PYSEC-2021-381.yaml"}],"tags":["osv","pip"],"epss":0.00758,"epssPercentile":0.53724,"ingestedAt":"2026-07-08T18:25:45.232Z","slug":"CVE-2021-41127","body":"## Overview\n\n### Impact\nAn Archive Extraction (Zip Slip) vulnerability in the functionality that allows a user to load a trained model archive in Rasa 2.8.9 and older allows an attacker arbitrary write capability within specific directories using a malicious crafted archive file.\n\n### Patches\nThe vulnerability is fixed in Rasa 2.8.10\n\n### Workarounds\nMitigating steps for vulnerable end users are to ensure that they do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email [the Rasa Security Team](mailto:security@rasa.com)\n\n\n## Affected packages\n\n- `rasa < 2.8.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `rasa 2.8.10`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}