PYSEC-2026-350
Dashboard / Vulnerabilities / PYSEC-2026-350
PYSEC-2026-350
Summary: External Control of File Name or Path in h2oai/h2o-3
Details: Remote unauthenticated attackers can overwrite arbitrary server files with attacker-controllable data. The data that the attacker can control is not entirely arbitrary. h2o writes a CSV/XLS/etc file to disk, so the attacker data is wrapped in quotations and starts with "C1", if they're exporting as CSV.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-6569, https://github.com/h2oai/h2o-3/commit/e8884f5187eb81311877c5f0dd4d6d9c70f33d78, https://github.com/h2oai/h2o-3, https://huntr.com/bounties/a5d003dc-c23e-4c98-8dcf-35ba9252fa3c, https://pypi.org/project/h2o, https://github.com/advisories/GHSA-gqrq-j6pm-98c2
Affected packages
Package
Name: h2o
Purl: pkg:pypi/h2o
Affected ranges
Type: ECOSYSTEM
Events:
