torchserve is vulnerable to Arbitrary File Write
75
High Risk
Affected versions of torchserve are vulnerable to a file write issue. Despite validating the URL, the targeted file via /models?url=<file_location> is still added to the models_store folder.
You are affected if you are use a vulnerable version of torchserve.
torchserve is vulnerable to Arbitrary File Write in versions 0.1.1 - 0.10.0.
Upgrade torchserve to the patch version (version 0.11.0).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant