Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cpq-gx29-gw6m

Опубликовано: 25 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

EPSS

Процентиль: 48%
0.00244
Низкий

10 Critical

CVSS4

Дефекты

CWE-22

Связанные уязвимости

debian

A path traversal vulnerability in the NPM package installation process ...

EPSS

Процентиль: 48%
0.00244
Низкий

10 Critical

CVSS4

Дефекты

CWE-22