context-mode is vulnerable to Path Traversal
75
High Risk
The plugin cache self-heal routine used a potentially attacker-influenced installPath from installed_plugins.json when creating symlinks/paths. The fix validates that the resolved path stays within ~/.claude/plugins/cache/, preventing path traversal to arbitrary filesystem locations. It also removes existing dangling symlinks before creating new ones to avoid unsafe symlink states.
You are affected if you are using a version that falls within the vulnerable range.
context-mode is vulnerable to Path Traversal in versions 1.0.96 - 1.0.96.
Upgrade the context-mode library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant