CVE-2024-10389

Severity CVSS v4.0:
MEDIUM
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
04/11/2024
Last modified:
23/07/2025

Description

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:safearchive:*:*:*:*:*:*:*:* 2024-10-25 (excluding)