ultralytics is vulnerable to Improper File Handling
74
High Risk
The package fixed multiple file-handling weaknesses by hardening ZIP/TAR extraction and validating ul:// platform URIs before use. It now blocks archive entries that would write outside the intended directory, skips symbolic links and other dangerous TAR members, and rejects ul:// paths containing absolute paths or .. traversal. These issues could otherwise enable arbitrary file overwrite, unauthorized file placement, or unsafe file access during download and extraction workflows.
You are affected if you are using a version that falls within the vulnerable range.
ultralytics is vulnerable to Improper File Handling in versions 8.0.30 - 8.4.41.
Upgrade the ultralytics library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant