Skip to content
H2O-3GHSA-gqrq-j6pm-98c2

External Control of File Name or Path in h2oai/h2o-3

Critical9.3CVE-2023-6569 · Published Dec 14, 2023 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
h2o
PyPI
< 3.46.0.13.46.0.1
Details and references

Remote unauthenticated attackers can overwrite arbitrary server files with attacker-controllable data. The data that the attacker can control is not entirely arbitrary. h2o writes a CSV/XLS/etc file to disk, so the attacker data is wrapped in quotations and starts with "C1", if they're exporting as CSV.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-610, CWE-73
Also known as
CVE-2023-6569, PYSEC-2026-350

More H2O-3 advisories

All H2O-3
DateAdvisory
Jun 62024Arbitrary system path lookup in h20
CVE-2024-5550Medium5.3no fix yet
Jun 272024h2o vulnerable to unexpected POST request shutting down server
CVE-2024-5979High7.5no fix yet
Sep 62024H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
CVE-2024-45758Critical9.1no fix yet
Mar 202025H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-10550High7.5no fix yet
Mar 202025H2O Deserialization of Untrusted Data Vulnerability
CVE-2024-10553Critical9.8fixed in 3.46.0.6
Mar 202025H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-10572High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.