{"id":"CVE-2024-10389","aliases":["GHSA-q3rp-vvm7-j8jg","GO-2024-3251"],"url":"https://o3.security/vulnerability/CVE-2024-10389","summary":"Path Traversal in Safearchive","details":"There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc","published":"2024-11-04T10:47:39.434Z","modified":"2026-07-15T01:49:10.604116858Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/google/safearchive","fixedVersion":"0.0.0-20241025131057-f7ce9d7b6f9c"}],"fix":{"url":"https://github.com/google/safearchive/commit/f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc","label":"google/safearchive@f7ce9d7"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10389.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10389"},{"type":"FIX","url":"https://github.com/google/safearchive/commit/f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc"},{"type":"PACKAGE","url":"https://github.com/google/Safearchive"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:10.604116858Z"}}