Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rvm-p3qm-f4vv

Опубликовано: 16 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

Smidge is vulnerable to Path Traversal

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The manipulation of the argument Version leads to path traversal. Remote exploitation of the attack is possible. Upgrading to version 4.6.0 is sufficient to resolve this issue. It is recommended to upgrade the affected component.

Пакеты

Наименование

Smidge

nuget
Затронутые версииВерсия исправления

< 4.6.0

4.6.0

EPSS

Процентиль: 25%
0.00087
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.3
nvd
4 месяца назад

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The manipulation of the argument Version leads to path traversal. Remote exploitation of the attack is possible. Upgrading to version 4.6.0 is sufficient to resolve this issue. It is recommended to upgrade the affected component.

EPSS

Процентиль: 25%
0.00087
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-22