Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3409 | The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This vulnerability stems from a GitHub Actions workflow artifact named .. when downloaded using gh run download. The artifact name and --dir flag are used to determine the artifact’s download path. When the artifact is named .., the resulting files within the artifact are extracted exactly 1 directory higher than the specified --dir flag value. This vulnerability is fixed in 2.63.1. |
Github GHSA |
GHSA-2m9h-r57g-45pj | Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability |
Ubuntu USN |
USN-8012-1 | GitHub CLI vulnerabilities |
Wed, 04 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Dec 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This vulnerability stems from a GitHub Actions workflow artifact named .. when downloaded using gh run download. The artifact name and --dir flag are used to determine the artifact’s download path. When the artifact is named .., the resulting files within the artifact are extracted exactly 1 directory higher than the specified --dir flag value. This vulnerability is fixed in 2.63.1. | |
| Title | GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-04T21:40:02.517Z
Reserved: 2024-11-29T18:02:16.754Z
Link: CVE-2024-54132
Updated: 2024-12-04T19:15:00.768Z
Status : Deferred
Published: 2024-12-04T16:15:26.730
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-54132
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:14:41Z
EUVD
Github GHSA
Ubuntu USN