HIGH7.1
PYSEC-2026-1436
H2O Vulnerable to Arbitrary File Overwrite via File Export
Details
In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a trained model file, although the content of the overwrite is not controllable by the attacker.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/h2o
Introduced in:
3.32.1.1No fixed version published yet for h2o (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-6854[ADVISORY]
- https://github.com/h2oai/h2o-3[PACKAGE]
- https://github.com/h2oai/h2o-3/blob/a20b5b19b769866ee24b217ee78b820e64c1cd6a/h2o-core/src/main/java/hex/Model.java#L3366[WEB]
- https://huntr.com/bounties/97d013f9-ac51-4c80-8dd7-8dfde11f33b2[WEB]
- https://pypi.org/project/h2o[PACKAGE]
- https://github.com/advisories/GHSA-47f6-5p7h-5f3h[ADVISORY]