CVE-2024-21542

High severity, CVSS 8.6. EPSS: 1.1% chance of exploitation in the next 30 days.

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.

Published 2024-12-10. Last modified 2026-06-17.