説明
Impact
A receiver who specifies "--output <dir>" where that output directory currently exists (as a directory).
Patches
0.24.0 will contain the patch
Workarounds
Ensure local target directories specified by "--output" do not already exist
Resources
Private email and Signal communications from a user.
Magic Wormhole thanks @marduc812
基本情報
- タイプ
- reviewed
- 深刻度
- low
- GitHub 上のアドバイザリ
- アドバイザリを開く ↗
- リポジトリのアドバイザリ
- リポジトリのアドバイザリを開く ↗
- ソースコード
- ソースを見る ↗
- 公開(アドバイザリ)
- 2026-05-06 20:40:17 UTC
- 更新
- 2026-06-08 23:28:05 UTC
- GitHub レビュー済み
- 2026-05-06 20:40:17 UTC
- NVD で公開
- 2026-05-26
EPSS Score
| Score |
Percentile |
|
0.04%
|
11.23% |
CVSS Scores
| Base score |
Version |
Severity |
Vector |
|
3.5
|
3.1 |
—
|
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
クリックして展開
- 攻撃ベクター (AV:N)
- インターネットなど、ルーティングされたネットワーク越しに遠隔から悪用しうる。端末の前にいる必要はない。
- 攻撃の複雑さ (AC:L)
- 攻撃者が条件を満たせば、レース条件や珍しい構成に依存せずに再現しやすい。
- 必要な権限 (PR:L)
- 一般ユーザー権限があれば足り、管理者(root 相当)は不要。
- ユーザーの関与 (UI:R)
- インストールの許可、設定変更、悪意あるファイルの実行など、人の一度の判断がトリガーになる。
- スコープ (S:U)
- 影響は脆弱コンポーネントと同一のセキュリティ権限・信頼境界の内側に収まる。
- 機密性への影響 (C:N)
- 機微情報の漏えいは想定しにくい。
- 完全性への影響 (I:L)
- レコードの一部書き換えや設定の歪みなど、限定的だが検知・復旧が必要な水準。
- 可用性への影響 (A:N)
- 業務継続に支障が出るレベルの停止や劣化は想定されない。
|
CWEs
| CWE id |
Name |
|
CWE-22
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Affected packages (1)
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem |
Package |
Vulnerable range |
First patched |
Vulnerable functions |
| pip |
magic-wormhole |
= 0.23.0 |
0.24.0 |
—
|
cvelogic
Threat Intelligence