Impact
A flaw exists in the code_task_files component of houtini-lm up to version 2.13.2 that fails to sanitize file paths. The vulnerability allows an attacker to craft input that leads to path traversal, potentially enabling them to access or manipulate files outside the intended directory. The vulnerability is exploitable remotely, meaning an attacker only needs network access to the service to trigger the flaw.
Affected Systems
Affected vendor and product: houtini-ai, houtini-lm. All releases up to and including version 2.13.2 are impacted. The patch commit 35d97bca0531894da36a85aedb95312da1bd5b7a has been issued to resolve the issue.
Risk and Exploitability
The CVSS score of 5.1 classifies the vulnerability as moderate. The EPSS score is currently unavailable, and it is not listed in CISA’s KEV catalog, indicating no confirmed large‑scale exploitation yet. Nevertheless, the remote attack surface and the potential to reveal or alter sensitive files make the risk material for systems that expose the code_task_files API to untrusted users or the internet. Administrators should treat the vulnerability as a priority for remediation.
OpenCVE Enrichment