github.com/axllent/ghru/v2 is vulnerable to Path Traversal
62
Medium Risk
Affected versions of this package are vulnerable to a path traversal in the archive extraction functionality. Specifically, archive entries containing crafted file paths (such as paths resolving outside the intended directory) could be extracted in a way that escapes the target directory, potentially overwriting or creating files in arbitrary locations. This behavior can be exploited by an attacker supplying a malicious archive to write or overwrite sensitive files on the host filesystem.
You are affected if you are using a version that falls within the vulnerable range.
github.com/axllent/ghru/v2 is vulnerable to Path Traversal in versions 2.0.0 - 2.0.2.
Upgrade the github.com/axllent/ghru/v2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant