-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/u-root/u-root/pkg/cpio | go | <= 7.0.0 |
The vulnerability stems from improper path sanitization during CPIO extraction. The pull request #1817 shows the fix involved changing path construction from filepath.Join(base, file) to a safer filepath.Join(base, filepath.Join("/", file)) pattern. This indicates CreateFile was the primary function handling file creation with unsafe path handling. The Snyk PoC demonstrates exploitation through archive processing via cpio.CreateFile, confirming this function's role in the vulnerability.
Ongoing coverage of React2Shell