{"id":"CVE-2024-21542","aliases":["GHSA-8qch-vj6m-2694","PYSEC-2024-159"],"url":"https://o3.security/vulnerability/CVE-2024-21542","summary":"luigi Arbitrary File Write via Archive Extraction (Zip Slip)","details":"Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.","published":"2024-12-10T05:00:01.546Z","modified":"2026-08-04T03:32:50.197480705Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"luigi","fixedVersion":"3.6.0"}],"fix":{"url":"https://github.com/spotify/luigi/commit/b5d1b965ead7d9f777a3216369b5baf23ec08999","label":"spotify/luigi@b5d1b96"},"references":[{"type":"WEB","url":"https://github.com/spotify/luigi/releases/tag/v3.6.0"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-LUIGI-7830489"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21542.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21542"},{"type":"REPORT","url":"https://github.com/spotify/luigi/issues/3301"},{"type":"FIX","url":"https://github.com/spotify/luigi/commit/b5d1b965ead7d9f777a3216369b5baf23ec08999"},{"type":"PACKAGE","url":"https://github.com/L3ster1337/Poc-CVE-2024-21542"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-04T03:32:50.197480705Z"}}