CVE-2025-10854

Source
https://cve.org/CVERecord?id=CVE-2025-10854
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10854.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-10854
Published
2025-09-22T12:04:51.805Z
Modified
2026-08-12T03:51:08.796230775Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indices
Details

The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is intended to prevent path traversal vulnerabilities by ensuring safe filenames, it does not account for symbolic links within the tar file. An attacker is able to write a file anywhere in the filesystem when txtai is used to load untrusted embedding indices

Database specific
{
    "cna_assigner": "JFROG",
    "cwe_ids": [
        "CWE-61"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10854.json"
}
References

Affected packages

Git / github.com/neuml/txtai

Affected ranges

Type
GIT
Repo
https://github.com/neuml/txtai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "9.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.5.0
v2.*
v2.0.0
v3.*
v3.0.0
v3.1.0
v3.2.0
v3.3.0
v3.4.0
v3.5.0
v3.6.0
v3.7.0
v4.*
v4.0.0
v4.1.0
v4.2.0
v4.2.1
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v5.*
v5.0.0
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.5.0
v5.5.1
v6.*
v6.0.0
v6.1.0
v6.2.0
v6.3.0
v7.*
v7.0.0
v7.1.0
v7.2.0
v7.3.0
v7.4.0
v7.5.0
v8.*
v8.0.0
v8.1.0
v8.2.0
v8.3.0
v8.3.1
v8.4.0
v8.5.0
v8.6.0
v9.*
v9.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10854.json"