Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0098 | Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function. |
Github GHSA |
GHSA-8qch-vj6m-2694 | luigi Arbitrary File Write via Archive Extraction (Zip Slip) |
Thu, 24 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 10 Feb 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
ssvc
|
Tue, 10 Dec 2024 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function. | |
| Weaknesses | CWE-29 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-07-24T13:07:39.995Z
Reserved: 2023-12-22T12:33:20.124Z
Link: CVE-2024-21542
Updated: 2024-12-16T19:14:42.561Z
Status : Deferred
Published: 2024-12-10T05:15:07.567
Modified: 2026-04-29T01:00:01.613
Link: CVE-2024-21542
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:24Z
EUVD
Github GHSA