CVE-2021-41127High· 7.3▾ TwilightMaliciously Crafted Model Archive Can Lead To Arbitrary File Write
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.8%
An Archive Extraction (Zip Slip) vulnerability in the functionality that allows a user to load a trained model archive in Rasa 2.8.9 and older allows an attacker arbitrary write capability within specific directories using a malicious crafted archive file.
The vulnerability is fixed in Rasa 2.8.10
Mitigating steps for vulnerable end users are to ensure that they do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.
If you have any questions or comments about this advisory:
rasa < 2.8.10Upgrade to a patched release:
rasa 2.8.10