← Back

Rasa

rasa

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Rasa
rasa
Rasa X
rasa_x

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rasa
1Rasa X
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories v...Show more
Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.Show less
1Rasa
1Rasa
Jun 17, 2026
Oct 21, 2021
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a vulnerability exists in the functionality that loads a trained model `tar.gz` file which allows a m...Show more
Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a vulnerability exists in the functionality that loads a trained model `tar.gz` file which allows a malicious actor to craft a `model.tar.gz` file which can overwrite or replace bot files in the bot directory. The vulnerability is fixed in Rasa 2.8.10. For users unable to update ensure that users do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.Show less