stanza is vulnerable to Path Traversal
78
High Risk
The unzip() helper in the resource management module extracts downloaded model and resource archives with ZipFile.extractall() and does not validate ZIP entry paths for directory traversal sequences. A crafted archive whose entries contain ../ can write files outside the intended extraction directory. When paired with a compromised or man-in-the-middled download server, an attacker can overwrite sensitive files such as shell startup scripts or SSH authorized_keys, leading to potential code execution. The fix validates that every archive member resolves inside the target directory before extraction.
You are affected if you are using a version that falls within the vulnerable range.
stanza is vulnerable to Path Traversal in versions 0.0.1 - 1.13.0.
Upgrade the stanza library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant