Intel

AIKIDO-2024-10061

ultralytics is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 29, 2024

90

Critical Risk

This Affects:

pythonultralytics
8.0.0 - 8.0.239
Fixed in 8.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper input validation, which could lead to command injection and path traversal. Exploiting this flaw may allow unauthorized execution of arbitrary commands and unauthorized access to files on the server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ultralytics is vulnerable to Improper Input Validation in versions 8.0.0 - 8.0.239.

How to fix this

Upgrade the ultralytics library to the patch version.