-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The GitHub commit 25f04f6 shows a security fix in ZipMisc.java where a path validation check was added during zip extraction. The vulnerability description explicitly mentions zip file extraction as the attack vector, and the CWE-22 classification confirms path traversal. The added code in the unzip function validates normalized paths to prevent directory escape, indicating this was the vulnerable function prior to the patch.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.diffplug.gradle:goomph | maven | < 3.37.2 | 3.37.2 |
Ongoing coverage of React2Shell