CVE-2022-31525 is a critical absolute path traversal vulnerability (CVSS 9.3) affecting SummaLabs/DLS repository versions through 0.1.0, including deep_learning_studio_project and deep_learning_studio. This flaw allows an unauthenticated attacker to access arbitrary files on the server due to the unsafe use of Flask's send_file function, potentially leading to high confidentiality impact and low availability impact. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, the vulnerability remains a significant risk due to its ease of exploitation and severe potential consequences.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:deep_learning_studio_project:deep_learning_studio:0.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.