{"id":"CVE-2023-48299","aliases":["GHSA-m2mj-pr4f-h9jp","PYSEC-2026-1972"],"title":"TorchServe ZipSlip","summary":"TorchServe ZipSlip","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","vendor":"torchserve","product":"torchserve","ecosystem":"pip","affected":["torchserve >= 0.1.0, < 0.9.0"],"patched":["torchserve 0.9.0"],"published":"2023-11-21","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:47.680388877Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-m2mj-pr4f-h9jp","references":[{"url":"https://github.com/pytorch/serve/security/advisories/GHSA-m2mj-pr4f-h9jp"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-48299"},{"url":"https://github.com/pytorch/serve/pull/2634"},{"url":"https://github.com/pytorch/serve/commit/bfb3d42396727614aef625143b4381e64142f9bb"},{"url":"https://github.com/pytorch/serve"},{"url":"https://github.com/pytorch/serve/releases/tag/v0.9.0"}],"tags":["osv","pip"],"epss":0.00679,"epssPercentile":0.50926,"ingestedAt":"2026-07-08T18:25:50.921Z","slug":"CVE-2023-48299","body":"## Overview\n\n### Impact\nUsing the model/workflow management API, there is a chance of uploading potentially harmful archives that contain files that are extracted to any location on the filesystem that is within the process permissions. Leveraging this issue could aid third-party actors in hiding harmful code in open-source/public models, which can be downloaded from the internet, and take advantage of machines running Torchserve.\n\n### Patches\nThe ZipSlip issue in TorchServe has been fixed by validating the paths of files contained within a zip archive before extracting them: https://github.com/pytorch/serve/pull/2634\n\nTorchServe release 0.9.0 includes fixes to address the ZipSlip vulnerability:\nhttps://github.com/pytorch/serve/releases/tag/v0.9.0\n\n### References\nhttps://github.com/pytorch/serve/pull/2634\nhttps://github.com/pytorch/serve/releases/tag/v0.9.0\n\n### Credit\nWe would like to thank Oligo Security for responsibly disclosing this issue.\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.\n\n## Affected packages\n\n- `torchserve >= 0.1.0, < 0.9.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `torchserve 0.9.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}