Skip to content
ZenMLGHSA-q92x-2x5g-h365

ZenML is vulnerable to Path Traversal through its `PathMaterializer` class

Medium6.3CVE-2025-8406 · Published Oct 5, 2025 · updated Jul 7, 2026

ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_directory` to validate files during `data.tar.gz` extraction, which fails to effectively detect symbolic and hard links. This vulnerability can lead to arbitrary file writes, potentially resulting in arbitrary command execution if critical files are overwritten.

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
>= 0.81.0, < 0.84.20.84.2
Details and references
CVSS 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2025-8406, PYSEC-2026-2071

More ZenML advisories

All ZenML
Advisory
ZenML unauthenticated DoS via Multipart Boundry
High7.5Mar 20, 2025
Missing ratelimit on passwrod resets in zenml
Medium5.4Nov 14, 2024
Reflected Cross-Site Scripting (XSS) in zenml
Medium6.1Jun 30, 2024
Improper line feed handling in zenml
Medium4.3Jun 24, 2024
zenml-io/zenml does not expire the session after password reset
Low3.9Jun 8, 2024
Improper authorization in zenml
Medium6.5Jun 6, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.