CRITICAL 9.3 PyPI

External Control of File Name or Path in h2oai/h2o-3

GHSA-gqrq-j6pm-98c2 · CVE-2023-6569 · PYSEC-2026-350

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Remote unauthenticated attackers can overwrite arbitrary server files with attacker-controllable data. The data that the attacker can control is not entirely arbitrary. h2o writes a CSV/XLS/etc file to disk, so the attacker data is wrapped in quotations and starts with "C1", if they're exporting as CSV.

Ready to move

Start Securing

Free, no credit card | First findings in minutes