Safearchive Path Traversal vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 4, 2024
to the GitHub Advisory Database
•
Updated Nov 6, 2024
Package
Affected versions
< 0.0.0-20241025131057-f7ce9d7b6f9c
Patched versions
0.0.0-20241025131057-f7ce9d7b6f9c
Description
Published by the National Vulnerability Database
Nov 4, 2024
Published to the GitHub Advisory Database
Nov 4, 2024
Reviewed
Nov 4, 2024
Last updated
Nov 6, 2024
There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
References