{"id":"CVE-2024-42471","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-42471","summary":"actions/artifact is the GitHub ToolKit for developing GitHub Actions.  Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using…","details":"actions/artifact is the GitHub ToolKit for developing GitHub Actions.  Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.","published":"2024-09-02T18:15:35.540","modified":"2026-06-17T07:49:30.840","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":{"url":"https://github.com/actions/toolkit/pull/1666","label":"actions/toolkit#1666"},"references":[{"type":"WEB","url":"https://github.com/actions/toolkit/pull/1666"},{"type":"ADVISORY","url":"https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3"},{"type":"WEB","url":"https://snyk.io/research/zip-slip-vulnerability"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T07:49:30.840"}}