torchserve is vulnerable to Arbitrary File Write
75
High Risk
Affected versions of torchserve are vulnerable to a file write issue. Despite validating the URL, the targeted file via /models?url=<file_location> is still added to the models_store folder.
You are affected if you are use a vulnerable version of torchserve.
torchserve is vulnerable to Arbitrary File Write in versions 0.1.1 - 0.10.0.
Upgrade torchserve to the patch version (version 0.11.0).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant