CVE-2024-10389: Google Safearchive

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

Affected products

  • Google Safearchive: before 2024-10-25 (fixed in 2024-10-25)

Published 2024-11-04. Last modified 2026-06-17.