google-cloud-storage is vulnerable to Path Traversal
60
Medium Risk
Affected versions of this package are vulnerable to a path traversal issue in download_many_to_path, where crafted blob names could cause files to be written outside the intended destination_directory. An attacker able to control blob names could exploit sequences like ../ to overwrite arbitrary files on the host filesystem, potentially leading to unauthorized file creation or modification. The issue is fixed by ensuring resolved download paths remain within the target directory and skipping unsafe blobs.
You are affected if you are using a version that falls within the vulnerable range.
google-cloud-storage is vulnerable to Path Traversal in versions 2.11.0 - 3.9.0.
Upgrade the google-cloud-storage library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant