Description
Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the href parameter.
Exploits (1)
Scores
EPSS
0.1236
EPSS Percentile
93.9%
Details
Status
published
Products (1)
h5ai_project/h5ai
< 0.24.1
Published
Sep 28, 2015
Tracked Since
Feb 18, 2026