Impact
The flaw resides in FileUtils.java within the MQTT message handling component of FedML-AI FedML. By manipulating the argument dataSet, an attacker can perform a path traversal attack, enabling reading or writing of files outside the intended directory. This weakness can compromise confidentiality and integrity of the system’s files and configuration.
Affected Systems
FedML-AI’s FedML product, versions up to and including 0.8.9, is affected. No further version details are supplied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS information is missing, and the vulnerability is not listed in the CISA KEV catalog. The description explicitly states the attack is possible remotely, likely via an MQTT interface that accepts a dataset parameter. An attacker who can send crafted MQTT messages could exploit the path traversal to gain unauthorized file access.
OpenCVE Enrichment