CVE-2024-10389: Google Safearchive
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
Affected products
- Google Safearchive: before 2024-10-25 (fixed in 2024-10-25)
Published 2024-11-04. Last modified 2026-06-17.